Security overview

Last updated: 13 August 2026

Security built for operational reality

Observata delivers managed security and observability services for organisations requiring clear visibility, controlled operations and rapid, practical response.

We unite active security operations, telemetry engineering and Elastic expertise to enable organisations to identify risks early, investigate incidents thoroughly and maintain operational stability across critical systems.

Delivery & deployment architecture

Observata's service frameworks accommodate diverse enterprise governance requirements:

  • Customer environment: Deployed directly within the customer's cloud tenant or on-premises infrastructure.
  • Observata-managed platform: Delivered via dedicated, isolated Observata infrastructure.
  • Hybrid deployment: Combining customer-retained data stores with managed operational and analytical layers.

Telemetry retention limits, data residency boundaries, platform availability metrics and service response tiers are defined within each client agreement.

Managed operations run throughout defined business hours, alongside 24/7 continuous monitoring and incident escalation for designated mission-critical services. Response thresholds and severity matrices are formalised via contract.

Identity, access & system governance

Administrative access to client tenants, operational systemsa and internal tooling is granted exclusively to vetted staff with clear business justification:

  • Multi-Factor Authentication (MFA): Enforced universally across all internal and administrative interfaces.
  • Role-Based Access Control (RBAC): Privileges are aligned strictly to role function.
  • Least privilege enforcement: Standing permissions are constrained; elevated administrative privileges are granted selectively and audited.
  • Continuous access re-evaluations: User rights are promptly revoked or adjusted upon personnel departures or role modifications.
  • Immutable audit records: Administrative access and configuration actions are captured in centralised, queryable log stores.

Data protection & cryptography

Customer telemetry and business data are safeguarded by layered organisational and technical controls:

  • Encryption in Transit: Data moving across public or unsegmented networks requires TLS 1.2 or TLS 1.3 cryptographic transport.
  • Encryption at Rest: Storage volumes, backups, and analytical indices use modern cryptographic standards (such as AES-256) where supported by the target environment.
  • Tenant isolation: Client data streams remain segmented across storage and retrieval pipelines.
  • Customer authority: Clients maintain ultimate authority over raw data, credential permissions, and system access policies based on the chosen deployment tier.

Monitoring, forensics & incident handling

Observata leverages centralised logging, behavioural analytics, and deep observability instrumentation to oversee service availability, investigate unusual activity and direct operational mitigations.

Our operations team follows documented incident playbooks and escalation workflows:

  • Anomalies are scored by potential severity, isolated, investigated and remediated according to our operational procedures.
  • Where required by contractual terms or data protection regulations (including the GDPR), we notify affected customers and statutory supervisory bodies of confirmed, material security incidents or personal data breaches within mandated deadlines.

Platform resilience & disaster recovery

We maintain backup, snapshot and continuity routines matched to system criticality and risk profiles. Recovery mechanisms undergo scheduled testing to ensure data integrity and dependable service restoration in emergency scenarios.

Supply chain risk & vendor audits

Every critical vendor and operational subcontractor undergoes thorough due diligence before onboarding, covering operational reliability, compliance posture and contractual safeguards.

Third-party processors handling customer data are catalogued in our public Sub-processor directory.

Reporting security findings

We welcome responsible disclosures regarding suspected vulnerabilities or security concerns.

Security Inquiries: legal@observata.com

Please do not include sensitive telemetry, system credentials or exploit material in initial email communications. Our security team will acknowledge receipt and establish a secure, encrypted channel for technical disclosures.