Yeah, that operational overhead point is exactly what I was worried about trying a trial. If they don't have a way to set the scope via API or Terraform from the start, you're already doing manual config cleanup before any real testing. It adds so much friction.
I checked their docs briefly for an API endpoint to push a clean config on agent install. Couldn't find one easily. Did you have any luck? That would be a huge red flag for automation.
Still learning.
Yeah, the memory usage is interesting. I ran it on a small GCP instance and saw similar spikes, especially during that initial aggressive scan. It's not massive, but it makes you wonder what else is running under the hood.
> data is retained for the trial duration plus 30 days "for analysis"
That's a really good catch. I glossed over the terms during my sign-up, too. A 30-day buffer after a security trial ends feels long, especially with no clear self-service purge. Did you find any way to actually delete your own data, or is it just a "contact support" thing?
It definitely feels demo-driven, which is disappointing for a security tool. Like they're prioritizing that "wow" factor on the dashboard over building trust from the first config.
Learning by breaking
"Analysis" is a convenient euphemism. It means repackaging your trial data for their own ML training or sales intelligence. You don't get a self-service purge because your data has value to them beyond your trial.
The retention is a bigger red flag than the YAML. The YAML is just sloppy. This is intentional.
Trust but verify.
That's a really important point about the IAM permissions. The principle of least privilege absolutely should start at onboarding. I haven't rolled it out in AWS yet, but I'm now hesitant to even start the trial without that clarity.
Could you share which similar tool you tested that had the overly broad policy? I'm trying to decide between Entro and a couple of other options, and knowing how their default IAM roles compare would help me understand which one respects security boundaries from the very first step.
The automatic wide-scope scan is exactly why I bail on most security tool trials after the first hour. It screams "we built this for sales engineers to run impressive demos, not for security engineers to evaluate safely."
You said the default targets local configs and cloud metadata endpoints. That's a massive assumption about my environment's trust boundary on day zero. A proper PAM tool should start by asking me to define my own perimeter, not guess at it based on what makes a dashboard pop.