Darktrace delivers its software through several components, and which of them a customer holds changes what has to be tracked, returned and operated. The Product Specification calls them topology components: physical appliances, cloud instances, virtual sensors and host agents. They can play the roles of Master, Probe, Unified View, Subordinate Master and Agent.[1] The MSA defines an “Appliance” as a hardware device, including embedded firmware, shipped by Darktrace to the customer and described in the Order.[2]
Physical appliances
Darktrace offers a physical appliance for installation in a data centre or other compatible location. Appliances are tuned hardware that host the Darktrace platform, run no other software, and come in several types with different throughput capacities and data ingestion options. The appropriate model depends on installation location, traffic volume, traffic composition and deployment role.[1] The appliance datasheet lists five models.[3]
| Model | Described use | Guidance maximum unique internal devices | Peak sustained throughput (Master) |
|---|---|---|---|
| DCIP-S | Small deployments; can act as a probe | 6,000 | 500 Mbps |
| DCIP-M | Small to medium companies | 30,000 | 3 Gbps |
| DCIP-X2 | Higher capacity; master or probe or standalone | 50,000 | 5 Gbps |
| DCIP-Z | Master at the core of a high-throughput deployment | 100,000 | 5 Gbps |
| DCIP-XA | Probe for high-bandwidth environments, with an FPGA network card | 50,000 | 20 Gbps |
The datasheet says these are “guidance numbers”, that exact performance depends on traffic and behaviour, and that sustained throughput at the stated maximums can cause overloading at peak times, so customers are advised to stay below them.[3] They are capacity guidance for choosing hardware. They are not the licensed Usage Metrics, which are set in the Order.[2] The catalog records them as Unique internal devices analysed.
Ownership and return
Title to all Appliances and their components remains with Darktrace unless agreed otherwise in writing. They are provided “solely as the medium for delivery and operation of the Software and must not be used for any other purpose.”[2] On termination or expiry of the Subscription Period or Evaluation Period, the customer must promptly return all Appliances to Darktrace or the Partner according to its instructions and ensure all Customer Data is removed. Darktrace is not responsible for configuration or data on the returned hardware.[1][2]
While the Appliance is in the customer’s possession the customer must store and use it properly, must not sell, charge, pledge, mortgage or otherwise dispose of it, must not permit any lien over it, and must keep it free from distress, execution and other legal process.[1] Because charges and liens are prohibited, appliances cannot form part of security granted over the customer’s assets, and an asset register should record them as Darktrace property. The datasheet notes that appliances have a physical security seal and that the cover should not be removed except by a Darktrace engineer or under their remote supervision.[1]
Delivery and cost
Darktrace uses commercially reasonable efforts to ship Appliances on the dates agreed in writing, and the customer’s sole remedy for delay is that delivery is made as soon as practicable. Delivery is FCA (Incoterms 2010) and, unless the Order says otherwise, the customer pays shipping, freight, customs and insurance. Darktrace may withhold or delay shipment if payment is late and may charge additional costs if the delivery site is not prepared.[1] Appliances must operate within thermal limits, with ambient inlet temperature never above 35 degrees Celsius, and all drive bays must be occupied.[1]
Operating duties
For physical appliances the customer is responsible for software updates, backups and other system health factors.[1] Backups can be configured automatically, with the three most recent retained locally by default, and exported over SCP, SMB or to an S3-compatible location; the Product Specification says it is a customer responsibility to configure them.[1] Backups include machine learning, models, model alerts, subnet and device information and configuration, but not transactional data such as the Event Log, Advanced Search entries or packet captures.[1] Transactional data typically has about 30 days of retention.[1]
Hardware support is provided under the Support Terms on a return-to-base basis with advance replacement, discussed in support, product-specific terms and managed services.[4]
Cloud-hosted instances
Darktrace can host a virtual Master in its own cloud environments on AWS and Microsoft Azure. Cloud Masters receive data from local Probes in the customer network, may analyse the same data as physical Masters, and are managed by Darktrace, which handles updates, backups and instance scaling. Cloud instances can run as Master or Unified View but cannot operate as Probes, so network traffic needs a Probe or vSensor.[1] Individual instances are provisioned per customer in the relevant cloud region and ingested data stays in the region.[1]
The Product Specification lists AWS regions in Europe, the United States, Canada, Singapore and Australia, and Azure regions in EMEA, the United States, Canada, South East Asia and Australia. A customer subject to regional data-flow restrictions must tell Darktrace if they would prevent use of any listed region. The cloud-hosted Master will not accept unencrypted data.[1] Under the MSA Darktrace may raise fees on 30 days’ notice, proportionately, if its cloud provider increases the charges it pays for services needed for the Offering.[2]
If automatic updates on a cloud Master are turned off at the customer’s request, the customer must tell Darktrace through the Customer Portal when it is ready to upgrade. In a hybrid Unified View with physical and cloud submasters, Darktrace manages the cloud Master and the customer manages the physical Masters.[1]
Virtual sensors and host agents
The vSensor is a virtual Probe for cloud-based or virtualised networks in which a physical Probe is not feasible or not wanted. Darktrace provides it in packaged virtual machine formats or as software installable on a compatible Linux virtual machine; the customer hosts it. It receives network traffic or syslog and forwards processed metadata to a connected Master, and the data it sends is approximately 1 to 4 percent of the traffic it ingests.[1] It requires at least two CPU cores and 2 GB of RAM, with more recommended, and a disk of at least 20 GB is recommended for packet captures.[1]
The osSensor is a lightweight, host-based agent for Windows and Linux, also offered in a container format for platforms such as Kubernetes and AWS Fargate. It forwards an unprocessed copy of network traffic to a vSensor and is not suitable over untrusted networks. A vSensor can be deployed with up to 255 osSensor agents.[1] The Server Agent is installed on servers hosting centralised applications and sends connection information to the Master.[1] Whether these components count toward a licensed quantity is not stated in the public documents. Adding the NETWORK License Key to a Master activates Autonomous Response on all connected vSensors.[1]
Call Home and updates
Call Home is a secure, encrypted channel from the Darktrace installation to Darktrace infrastructure over TCP port 443. When it is enabled, Master appliances are automatically upgraded to the latest Threat Visualizer release unless an approval requirement has been registered, and models are updated automatically.[1] The Support Terms say remote analyst support depends on Call Home access and that “disabling Call Home will impact Darktrace’s ability to perform Support Services.”[4] Software releases are subject to a Product Support and End of Life Policy that is published in the Customer Portal.[1][4]
What happens at the end of the term
On termination the customer must cease use, de-install the Software, remove Customer Data from any Appliance and return it. For 30 days Darktrace maintains data stored in its cloud services and gives access to download and delete it, after which the data is deleted and cannot be recovered.[2] An appliance that is not returned remains Darktrace property, and the support terms oblige the customer to return all parts originally shipped when exchanging failed hardware, including rails, transceivers and power cables.[4]
Out of scope
This article does not cover the appliance safety certifications, power consumption, the network access port tables or the vSensor operating system requirements beyond the figures quoted. It does not cover ENDPOINT cSensor agents, which the Product Specification mentions but does not define.[1]