OptimusHub is purpose-built for environments where regulatory compliance is non-negotiable. By keeping your entire DevOps stack self-hosted and air-gap capable, the platform eliminates the data residency and audit risks that come with SaaS-based tooling.
Most DevOps platforms were designed for public cloud and then adapted — imperfectly — for regulated on-premises environments. OptimusHub takes the opposite approach: it runs entirely within your infrastructure, under your governance model, with no mandatory external dependencies.
This means:
OptimusHub is designed to help organisations meet the technical control requirements of the following frameworks. Note that platform support does not constitute certification — achieving and maintaining compliance requires organisational and procedural controls in addition to technical ones.
On-premises deployment ensures data residency within the EU (or your jurisdiction). No personal data is transferred to third-party cloud providers through normal platform operation. Data subject rights can be fulfilled by your DBA/admin team through direct access controls.
Platform controls directly address Annex A domains including access control (A.9), cryptography (A.10), operations security (A.12), and supplier relationships (A.15). Audit logs provide evidence for Information Security Management System (ISMS) audits.
Centralised audit logging, RBAC enforcement, MFA, and credential governance address Trust Services Criteria for Security (CC6, CC7) and Availability (A1). Logs are structured and exportable for auditor review.
Air-gapped or on-premises deployment supports ePHI data residency requirements. Access controls, session management, and audit trails address the HIPAA Security Rule's Technical Safeguards. No ePHI is processed by OptimusHub itself.
Control families addressed include AC (Access Control), AU (Audit and Accountability), IA (Identification and Authentication), SC (System and Communications Protection), and SI (System and Information Integrity). Suitable for government-adjacent deployments requiring FedRAMP-aligned controls.
Supports network segmentation, least-privilege access, audit trail requirements, and credential management relevant to protecting cardholder data environments (CDE). OptimusHub does not process, store, or transmit payment card data.
Every user action, API call, and administrative change is recorded with full attribution: user identity, timestamp, source IP, resource affected, and result. Logs are structured (JSON), tamper-resistant, and exportable to your SIEM of choice.
Granular role assignments at platform, project, and resource level. New principals receive zero permissions by default. Permissions are explicitly granted, documented in audit logs, and reviewable via the admin interface.
Platform-level MFA enforcement — not per-app or optional. TOTP-based authentication required for all privileged operations. Integration with your existing IdP means MFA policies you've already defined carry through.
The platform operates with zero mandatory external network calls. All container images, Helm charts, and platform dependencies can be mirrored to an internal registry. Air-gap mode is a first-class deployment configuration, not an unsupported edge case.
SSH keys, kubeconfigs, and API tokens are stored encrypted, scoped to individual users or service accounts, and rotatable on demand or on schedule. Access to credentials is logged and can trigger alerts.
Integrate with LDAP, Active Directory, or OIDC-compliant providers (Keycloak, Dex, Okta on-prem). Users authenticate against your existing directory; no shadow accounts to manage or synchronise.
Audit and operational logs can be forwarded via syslog, Loki, or webhook to your existing SIEM (Splunk, Elastic, IBM QRadar, Microsoft Sentinel). Log schema is documented for rule and alert authoring.
Platform administrator, project owner, developer, and read-only roles are pre-defined and configurable. Critical operations (credential deletion, cluster access grant, user promotion) require elevated roles and generate audit events.
We understand that procurement in regulated environments involves detailed security questionnaires, architecture reviews, and evidence collection. We support this process with:
For the operational detail behind these evaluations, see air-gapped infrastructure operations and hybrid infrastructure operations.
OptimusHub is a tool that enables compliance — it does not guarantee it. Compliance outcomes depend on how the platform is configured and operated. Specifically:
Evaluating OptimusHub for a regulated environment?
Talk to us and we'll walk through the specific controls relevant to your framework and discuss your deployment requirements.
For compliance-related questions, security questionnaires, or to request our architecture documentation: