Documentation

Install

What the install script does, in the order it does it.

Requirements

  • root (sudo).
  • systemd, and the base tools every server has: curl, openssl, sha256sum, base64.
  • OpenSSL 3.0 or later, because the script verifies an Ed25519 signature with a command that OpenSSL 1.1.1 does not have. Debian 12, Ubuntu 22.04 and the Enterprise Linux 9 family ship OpenSSL 3; releases older than those cannot pass that step, and the installer stops rather than install a binary it could not verify.

The script, step by step

  • Downloads the release binary for your enrolment token's organisation and release channel.
  • Checks the download's SHA-256 against the value baked into the script.
  • Verifies an Ed25519 signature over the binary with the release public key (printed in the Trust Center).
  • Moves the binary to /usr/local/bin/security-agent.
  • Writes /etc/systemd/system/secai-agent.service (User=root, Restart=always) and a survival drop-in that protects the agent from the OOM killer.
  • Writes /etc/logrotate.d/secai-agent, enables and starts the service.

Read it first

The script is plain shell. Fetch it with the same URL without piping to bash, read it, then run it. The platform refuses to serve a release whose signature does not verify, so an unsigned binary cannot be handed out even by mistake.

curl -fsSL "https://secai.techsteps.ae/agent/install.sh?token=<token>" -o secai-install.sh
less secai-install.sh
sudo bash secai-install.sh

Where things go

Binary
/usr/local/bin/security-agent (previous release kept at /usr/local/bin/security-agent.prev)
Service
secai-agent (systemd)
Identity and enrolment
/etc/securityemployee
Update and policy state
/etc/securityemployee-agent
Configuration copies for undo
/var/lib/securityemployee/snapshots
Logs
journalctl -u secai-agent; updates in /var/log/securityemployee-agent-update.log

Reviewed against the implementation on 2026-09-20. Something wrong? Tell us.

Trust Center