Documentation
Network requirements
Outbound HTTPS to one host. No inbound port.
Outbound
- secai.techsteps.ae, TCP 443
- Telemetry, heartbeats, commands, updates. Required.
- 1.1.1.1 and 9.9.9.9, TCP 443
- Only after three consecutive failures to reach SecAI: a connection is opened and closed with no data, to tell "SecAI unreachable" from "link down". Optional; if blocked, the agent reports the outage as unknown.
- Your distribution's mirrors
- Only when a package install is approved; the system package manager fetches as it normally does.
Inbound
None. The agent opens no listening port.
DNS
The agent resolves secai.techsteps.ae with the system resolver and keeps the last known address, so a resolver failure during an outage does not stop it reaching SecAI.
Behind a proxy or egress filter
Allow HTTPS to secai.techsteps.ae. The service unit sets no proxy variables; if egress must go through an HTTP proxy, add Environment=HTTPS_PROXY=http://proxy:port in a systemd drop-in for secai-agent (the HTTP client honours it) and restart the service.
Reviewed against the implementation on 2026-09-20. Something wrong? Tell us.