Security and Compliance at Omnistrate¶
Omnistrate delivers enterprise-grade security and compliance for your SaaS products across all deployment channels. Our platform is designed to help you implement robust security controls, maintain governance, and meet industry standards with ease.
For the latest information about Omnistrate's security posture, compliance status, controls, and available assurance documents, visit the Omnistrate Trust Center.
Our Security Practices¶
- SOC 2 Type II: Omnistrate has successfully completed an independent SOC 2 Type II attestation, demonstrating that our security controls are appropriately designed and operate effectively over time. This independent assurance helps customers confidently build and operate secure SaaS products on Omnistrate. For more details, see our Type I and Type II announcements.
- ISO/IEC 27001: Omnistrate is ISO/IEC 27001 certified, demonstrating that its information security management system meets the requirements of the international standard.
- EU GDPR: Omnistrate maintains technical and organizational controls designed to support compliance with the European Union General Data Protection Regulation.
- HIPAA: Omnistrate maintains security and privacy controls designed to support workloads subject to the Health Insurance Portability and Accountability Act.
- Penetration Testing: We conduct regular penetration tests and make reports available upon request to ensure ongoing security and risk mitigation.
- Vulnerability Reporting: If you discover a security issue or vulnerability, please contact us at [email protected]. We will coordinate with you to securely address and resolve any concerns.
SOC 2 and ISO/IEC 27001 provide independent assurance of Omnistrate's controls. GDPR and HIPAA are regulatory frameworks and should not be interpreted as certifications. Your organization's compliance remains a shared responsibility based on how you configure, deploy, and operate your application.
Key Security Features¶
- Cloud Account Permissions: Permissions required to access your and your customers' cloud accounts, following minimum privilege principles
- Role-Based Access Control (RBAC): Enforce security policies to restrict access to resources and actions based on user roles and organizational context
- API Keys: Long-lived, org-scoped credentials for automation, CI/CD, and service-to-service authentication
- Secrets Management: Secure handling of sensitive configuration
- Customer Networks: Network isolation and VPC integration
- Customer-Controlled BYOC Access: Controls for AWS infrastructure and Kubernetes access, including customer-managed access for BYOC On-Premise clusters
- SSO / Identity Providers: Enterprise authentication and identity management
- Operational Status Page: Communicate real-time status to your users
- Audit Logs: Track user actions and system events across your SaaS products for accountability and compliance
Customer-Controlled BYOC Governance¶
AWS BYOC¶
For AWS BYOC accounts, the customer account owner retains control over Omnistrate's operational access through the customer-owned AccountConfigSetup CloudFormation stack. Changes to these controls are recorded in the account's CloudFormation history.
The available controls include:
- AWS infrastructure mutation: Allow the permissions required for normal provisioning and lifecycle operations, or apply an explicit deny to non-read AWS actions while preserving read-only inspection.
- Dataplane Kubernetes permissions: For BYOC PrivateLink host clusters, grant the dataplane agent administrative access for normal lifecycle operations or restrict it to read-only access.
- Kubernetes debug access: For BYOC PrivateLink host clusters, enable or disable the network path Omnistrate uses for Kubernetes debug access.
- Targeted enforcement: Apply the Kubernetes permission and debug-access controls across all supported host clusters, within selected AWS regions, or to individual host clusters.
Restricting infrastructure mutation or Kubernetes write access can block provisioning, updates, scaling, repairs, and deletion operations that require those permissions. For parameter values, targeting formats, update instructions, and verification, see AWS CloudFormation Account Controls. For the private connectivity model, see BYOC PrivateLink.
BYOC On-Premise¶
For BYOC On-Premise, the customer controls Omnistrate's access by controlling the dataplane agent Helm release in their Kubernetes cluster. The agent initiates an outbound connection to the Omnistrate control plane; customers do not need to expose the Kubernetes API server publicly.
- Revoke access: Uninstall the
dp-agentHelm release from thedataplane-agentnamespace. This disconnects the agent without uninstalling the customer's product workloads, but Omnistrate can no longer monitor or perform lifecycle operations in the cluster. - Grant or restore access: Generate a fresh install kit for the customer onboarding instance and run the Helm install command included in the kit. The generated
values.yamlcontains the account-specific agent configuration, so use the kit for the intended account and cluster.
For the commands and verification steps, see Control Omnistrate Access.
Compliance Resources¶
The resources in this section help you evaluate Omnistrate's controls and support your own security and compliance programs. Using Omnistrate does not automatically certify your application or self-service portal.
- Trust Center: Review current compliance frameworks and security controls, and request access to available reports and assurance documents in the Omnistrate Trust Center.
- SOC 2 for your control plane: Use Omnistrate's independently attested controls and supporting documentation as inputs to your SaaS product's own SOC 2 program.
- Security questionnaire: Access a common compliance questionnaire report, including resources like the AWS FTR checklist, to streamline your review process.
- Pen test report: Review details about our penetration testing program. If you require a custom report, please contact [email protected] for assistance.
Reporting Security Issues¶
Note
If you have a security concern or believe you have found a vulnerability in any part of our infrastructure, please contact us at [email protected]. We will work with you to coordinate the secure exchange of sensitive information.