🔒 OptimusHub is SOC 2 ready — built for air-gapped and regulated environments
← Back to OptimusHub

Security

Last updated: May 2026

SOC 2
Ready

OptimusHub is built to SOC 2 Type II standards — immutable audit trail, encrypted secrets management, RBAC with least-privilege enforcement, SSO with MFA, and internal PKI — all included in the platform, not bolt-ons. We are available to share our security controls documentation and architecture review materials with enterprise customers under NDA.

OptimusHub is designed from the ground up for high-security, regulated, and air-gapped environments — including sovereign infrastructure, defense networks, and organizations where public cloud access is not permitted or not desired. Security is a first-class platform concern at every layer of the architecture.

SOC 2 Ready Air-Gap Native Self-Hosted Zero External Telemetry Immutable Audit Trail Fernet-Encrypted Vault Built-In PKI / CA TLS 1.2+

1. Deployment Architecture

OptimusHub runs entirely within your infrastructure. The platform has no mandatory external dependencies — it is designed to operate with zero internet egress in fully air-gapped environments.

2. SOC 2 Alignment

OptimusHub is architected to satisfy the Trust Services Criteria for Security (CC), Availability (A), and Confidentiality (C) under AICPA SOC 2. The following controls are native to the platform:

CC6 — Logical Access RBAC with least-privilege defaults. Namespace-level Kubernetes access grants. SSO with MFA enforcement. All access explicitly granted, never inherited.
CC7 — System Operations Immutable audit trail for every platform action. Alert rules with SMTP delivery. Deployment log streaming and SSH session audit.
CC8 — Change Management All deployments, Helm releases, and configuration changes are logged with actor identity, timestamp, and result. Changes are traceable and attributable.
CC9 — Risk Mitigation Encrypted secrets vault. Internal PKI/CA for certificate lifecycle. No single-point secrets exposure — credentials never appear in logs or API responses after creation.
A1 — Availability DR planning with RTO/RPO targets, DRS affinity groups, and database backup policies with encrypted storage and cron scheduling.
C1 — Confidentiality Fernet-encrypted secrets vault. TLS 1.2+ in transit. AES-256 at rest. Scoped credential access with expiry. No data leaves the customer's environment.

3. Identity and Access Control

Role-Based Access Control (RBAC) Three built-in roles plus custom roles with granular per-feature permissions. Namespace-level Kubernetes access grants — viewer or manager per namespace per user.
Multi-Factor Authentication (MFA) MFA enforcement at the platform level for all users. TOTP-based authenticators supported. Configurable enforcement policies per role or group.
SSO — LDAP, OIDC, SAML Native integration with LDAP, Active Directory, OIDC-compatible providers (Keycloak, Dex, Okta), and SAML 2.0. Group-to-role mapping supported across all providers.
Secrets & Credential Vault Built-in Fernet-encrypted vault for SSH keys, kubeconfigs, API tokens, registry credentials, and database connection strings. Scoped access with expiry policies.
Session Controls Configurable session timeouts and automatic logout. All active sessions are visible and revocable by administrators. Session activity is included in the audit log.
Least-Privilege Defaults New users and service accounts receive no permissions by default. Access is explicitly granted through roles or group mappings — never assumed or inherited.

4. Secrets Management & Internal PKI

OptimusHub includes a built-in secrets vault and a full internal Certificate Authority — no third-party tools required.

Secrets Vault

Internal Certificate Authority (PKI)

5. Data Protection

Encryption in Transit

All communication between the OptimusHub frontend, control plane API, and managed infrastructure uses TLS 1.2 or higher. Internal service-to-service communication within the platform is encrypted. WebSocket SSH sessions are encrypted end-to-end through the platform's authenticated tunnel proxy.

Encryption at Rest

Sensitive data — including secrets, SSH keys, kubeconfigs, and database credentials — is encrypted at rest. Encryption keys are managed within your environment and never leave your control plane. Database backup files are stored with encryption enabled by default.

6. Immutable Audit Trail

Every action within OptimusHub — by users, administrators, service accounts, and automated processes — is recorded in a tamper-evident, append-only audit log. Records include:

Audit logs cannot be edited or deleted through the standard platform UI. They are exportable as structured JSON and can be forwarded to external SIEM systems (Splunk, Elastic, Grafana Loki) via syslog or webhook. This audit architecture is designed to satisfy SOC 2 CC7 and support forensic investigation requirements.

7. Kubernetes Security

OptimusHub enforces security guardrails across all managed Kubernetes clusters:

8. Network Security

For the full operational picture of running in a disconnected network, see air-gapped infrastructure operations.

9. Operational Security of This Website

The OptimusHub marketing website (optimushub.net) is served as a static build via Nginx with the following controls:

10. Responsible Disclosure

Security Vulnerability Reporting

If you discover a security vulnerability in OptimusHub or on this website, please report it responsibly before any public disclosure. We take all reports seriously and will respond promptly.

Contact: [email protected]

Please include in your report:

Our commitment:

11. Security Contact

For security-related questions, vulnerability reports, SOC 2 documentation requests, or to discuss our security architecture during a procurement evaluation:

Enterprise customers requiring a security architecture review, controls documentation, or a dedicated walkthrough of our SOC 2 posture should contact [email protected]. We are happy to provide detailed materials under NDA.