That auditability gap is real. We ended up scraping the vendor's own agent status API to create a Grafana dashboard showing policy hash mismatch counts across AZs. The console showed green, but we had a 7% laggard group for almost three minutes on every push. Turns out their batch update system would skip instances under high load.
> does their playbook automatically copy that dump to a US-based sandbox
You've put your finger on the exact trap. We got burned by this. The memory dump stayed in-region, but the automated malware analysis service, which was a "feature," pulled a copy to their US SOC for "faster classification." It was buried in a sub-processor annex from 18 months prior. Legal missed it completely.
That's a really good point about the "learning period" causing recurring tuning work. It sounds like a hidden ops tax.
The forensic data location got me thinking, thanks. If their analysis portal is US-based, does that mean even the metadata about the dump, like filenames or process lists, gets transferred? That could still be a problem, right?