Configuration

Configuration

Configuration and Defaults

What This Covers

This page explains how Steel Security handles configuration and why it does not include traditional plugin settings.

Steel Security is designed to minimize configuration and provide safe, effective defaults out of the box.


No Settings by Design

Steel Security does not include a traditional settings panel.

This is intentional.

The plugin is designed to:

Most functionality is controlled through actions, not settings.


How Steel Security Is Configured

Instead of settings, Steel Security operates through:

This means:


Why There Are No Settings

Traditional settings often:

Steel Security avoids this by using:


What You Can Control

While there are no global settings, you still have full control over:

This keeps control focused on decisions that matter.


Benefits of This Approach

This approach is especially beneficial for:


When Configuration May Still Be Needed

Some actions may still involve environment-specific decisions, such as:

These are handled outside of Steel Security where appropriate.


Common Questions

Why can’t I customize scan behavior?

Steel Security focuses on high-signal checks that are relevant across most environments.

Reducing configurability helps ensure consistent and meaningful results.


Will settings be added in the future?

Steel Security prioritizes clarity and safety over configurability.

New options will only be introduced where they provide clear value without increasing complexity.


How do I change how Steel Security behaves?

Behavior is controlled through:


Tips


What to Do Next

Now that you understand how Steel Security is configured:

  1. Run a scan
  2. Review findings
  3. Apply hardening as needed