Documentation

Network requirements

Outbound HTTPS to one host. No inbound port.

Outbound

secai.techsteps.ae, TCP 443
Telemetry, heartbeats, commands, updates. Required.
1.1.1.1 and 9.9.9.9, TCP 443
Only after three consecutive failures to reach SecAI: a connection is opened and closed with no data, to tell "SecAI unreachable" from "link down". Optional; if blocked, the agent reports the outage as unknown.
Your distribution's mirrors
Only when a package install is approved; the system package manager fetches as it normally does.

Inbound

None. The agent opens no listening port.

DNS

The agent resolves secai.techsteps.ae with the system resolver and keeps the last known address, so a resolver failure during an outage does not stop it reaching SecAI.

Behind a proxy or egress filter

Allow HTTPS to secai.techsteps.ae. The service unit sets no proxy variables; if egress must go through an HTTP proxy, add Environment=HTTPS_PROXY=http://proxy:port in a systemd drop-in for secai-agent (the HTTP client honours it) and restart the service.

Reviewed against the implementation on 2026-09-20. Something wrong? Tell us.

Trust Center