← Back to OptimusHub

Compliance

Last updated: February 2026

OptimusHub is purpose-built for environments where regulatory compliance is non-negotiable. By keeping your entire DevOps stack self-hosted and air-gap capable, the platform eliminates the data residency and audit risks that come with SaaS-based tooling.

1. Compliance-First Architecture

Most DevOps platforms were designed for public cloud and then adapted — imperfectly — for regulated on-premises environments. OptimusHub takes the opposite approach: it runs entirely within your infrastructure, under your governance model, with no mandatory external dependencies.

This means:

2. Regulatory Framework Support

OptimusHub is designed to help organisations meet the technical control requirements of the following frameworks. Note that platform support does not constitute certification — achieving and maintaining compliance requires organisational and procedural controls in addition to technical ones.

GDPR

On-premises deployment ensures data residency within the EU (or your jurisdiction). No personal data is transferred to third-party cloud providers through normal platform operation. Data subject rights can be fulfilled by your DBA/admin team through direct access controls.

ISO 27001

Platform controls directly address Annex A domains including access control (A.9), cryptography (A.10), operations security (A.12), and supplier relationships (A.15). Audit logs provide evidence for Information Security Management System (ISMS) audits.

SOC 2 Type II

Centralised audit logging, RBAC enforcement, MFA, and credential governance address Trust Services Criteria for Security (CC6, CC7) and Availability (A1). Logs are structured and exportable for auditor review.

HIPAA

Air-gapped or on-premises deployment supports ePHI data residency requirements. Access controls, session management, and audit trails address the HIPAA Security Rule's Technical Safeguards. No ePHI is processed by OptimusHub itself.

NIST SP 800-53 / FedRAMP

Control families addressed include AC (Access Control), AU (Audit and Accountability), IA (Identification and Authentication), SC (System and Communications Protection), and SI (System and Information Integrity). Suitable for government-adjacent deployments requiring FedRAMP-aligned controls.

PCI DSS

Supports network segmentation, least-privilege access, audit trail requirements, and credential management relevant to protecting cardholder data environments (CDE). OptimusHub does not process, store, or transmit payment card data.

3. Platform Compliance Capabilities

Centralised Audit Logging

Every user action, API call, and administrative change is recorded with full attribution: user identity, timestamp, source IP, resource affected, and result. Logs are structured (JSON), tamper-resistant, and exportable to your SIEM of choice.

RBAC with Least-Privilege Enforcement

Granular role assignments at platform, project, and resource level. New principals receive zero permissions by default. Permissions are explicitly granted, documented in audit logs, and reviewable via the admin interface.

Multi-Factor Authentication

Platform-level MFA enforcement — not per-app or optional. TOTP-based authentication required for all privileged operations. Integration with your existing IdP means MFA policies you've already defined carry through.

Data Sovereignty

The platform operates with zero mandatory external network calls. All container images, Helm charts, and platform dependencies can be mirrored to an internal registry. Air-gap mode is a first-class deployment configuration, not an unsupported edge case.

Credential and Secrets Governance

SSH keys, kubeconfigs, and API tokens are stored encrypted, scoped to individual users or service accounts, and rotatable on demand or on schedule. Access to credentials is logged and can trigger alerts.

Identity Provider Integration

Integrate with LDAP, Active Directory, or OIDC-compliant providers (Keycloak, Dex, Okta on-prem). Users authenticate against your existing directory; no shadow accounts to manage or synchronise.

SIEM and Log Forwarding

Audit and operational logs can be forwarded via syslog, Loki, or webhook to your existing SIEM (Splunk, Elastic, IBM QRadar, Microsoft Sentinel). Log schema is documented for rule and alert authoring.

Separation of Duties

Platform administrator, project owner, developer, and read-only roles are pre-defined and configurable. Critical operations (credential deletion, cluster access grant, user promotion) require elevated roles and generate audit events.

4. Compliance Evaluation Support

We understand that procurement in regulated environments involves detailed security questionnaires, architecture reviews, and evidence collection. We support this process with:

For the operational detail behind these evaluations, see air-gapped infrastructure operations and hybrid infrastructure operations.

5. Limitations and Shared Responsibility

OptimusHub is a tool that enables compliance — it does not guarantee it. Compliance outcomes depend on how the platform is configured and operated. Specifically:

Evaluating OptimusHub for a regulated environment?
Talk to us and we'll walk through the specific controls relevant to your framework and discuss your deployment requirements.

Talk to us about your operating environment →

6. Contact

For compliance-related questions, security questionnaires, or to request our architecture documentation: