Learn
Optra Security
Security commitments, controls, and hardening practices across the Optra platform.
Optra is built with a security-first mindset across development, operations, and customer support engagement. Our security model combines endpoint and cloud security tooling, secure software development lifecycle (SSDL) practices, and continuous hardening to reduce risk throughout delivery.
Security in Optra is not isolated to one stage of development. It is embedded across code scanning, platform operations, centralized monitoring, and release processes so that controls are continuously applied and regularly improved.
How Optra Security Works
Security Tooling
Endpoint and cloud controls include Tenable, Microsoft Defender, and Wiz, supported by ongoing security validation.
Centralized Visibility
Security logs are routed to enterprise SOC workflows and an Optra-managed support view for customer-facing incident handling.
Continuous Hardening
Upgrades, threat model updates, and infrastructure hardening are treated as recurring operational responsibilities.
Security Agents and Scope
The following agents are currently installed in the subscription:
TenableMicrosoft DefenderWiz
XDR Scope Clarification
Cybersecurity requested XDR installation on virtual machines. During validation, the target infrastructure was identified as AKS nodes. Based on that architecture, cybersecurity confirmed XDR installation was out of scope for those nodes.
Logging, Monitoring, and Incident Visibility
Optra forwards security logs to the following destinations:
- IT-owned
Microsoft Sentinel - A dedicated Optra Sentinel instance for customer engagement and support
This dual-visibility model supports enterprise governance while preserving rapid support workflows for customer-facing operations.
Security Scans and Controls
Optra applies layered security checks throughout development and release:
Sobelow(Phoenix-focused static security analysis): every commitBurp Suite: during SSDL activitiesOWASPsecurity checks: during SSDL activities- GitHub Security Agent: ongoing proof of concept
- Security header validation: during release
Secure Development and Hardening
Core Principle
Upgrade all things.
This includes continuously patching and upgrading:
- Programming languages
- Libraries and dependencies
- Runtime and platform components
Current Strengths
- Strong upgrade discipline for programming languages and libraries
Current Improvement Focus
- Kubernetes hardening
- Base container image hardening
- Service-level hardening
- Threat model updates as part of SSDL
How Security Is Embedded in Optra Delivery
Security is integrated into day-to-day engineering and release workflows:
- Code is scanned continuously and at key SSDL checkpoints.
- Platform and service security posture is reviewed and improved iteratively.
- Logs are centralized for both enterprise SOC workflows and Optra support needs.
- Threat models are reviewed and updated to reflect architecture and risk changes.
- Upgrades are treated as standard operations, not one-time tasks.
Summary
Optra security combines proactive tooling, centralized monitoring, and a practical hardening roadmap. The platform maintains strong dependency and language hygiene today while actively advancing Kubernetes, container, and service hardening to further strengthen security posture.