Learn

Optra Security

Security commitments, controls, and hardening practices across the Optra platform.

Optra is built with a security-first mindset across development, operations, and customer support engagement. Our security model combines endpoint and cloud security tooling, secure software development lifecycle (SSDL) practices, and continuous hardening to reduce risk throughout delivery.

Security in Optra is not isolated to one stage of development. It is embedded across code scanning, platform operations, centralized monitoring, and release processes so that controls are continuously applied and regularly improved.

How Optra Security Works

Security Tooling

Endpoint and cloud controls include Tenable, Microsoft Defender, and Wiz, supported by ongoing security validation.

Centralized Visibility

Security logs are routed to enterprise SOC workflows and an Optra-managed support view for customer-facing incident handling.

Continuous Hardening

Upgrades, threat model updates, and infrastructure hardening are treated as recurring operational responsibilities.

Security Agents and Scope

The following agents are currently installed in the subscription:

  • Tenable
  • Microsoft Defender
  • Wiz

XDR Scope Clarification

Cybersecurity requested XDR installation on virtual machines. During validation, the target infrastructure was identified as AKS nodes. Based on that architecture, cybersecurity confirmed XDR installation was out of scope for those nodes.

Logging, Monitoring, and Incident Visibility

Optra forwards security logs to the following destinations:

  • IT-owned Microsoft Sentinel
  • A dedicated Optra Sentinel instance for customer engagement and support

This dual-visibility model supports enterprise governance while preserving rapid support workflows for customer-facing operations.

Security Scans and Controls

Optra applies layered security checks throughout development and release:

  • Sobelow (Phoenix-focused static security analysis): every commit
  • Burp Suite: during SSDL activities
  • OWASP security checks: during SSDL activities
  • GitHub Security Agent: ongoing proof of concept
  • Security header validation: during release

Secure Development and Hardening

Core Principle

Upgrade all things.

This includes continuously patching and upgrading:

  • Programming languages
  • Libraries and dependencies
  • Runtime and platform components

Current Strengths

  • Strong upgrade discipline for programming languages and libraries

Current Improvement Focus

  • Kubernetes hardening
  • Base container image hardening
  • Service-level hardening
  • Threat model updates as part of SSDL

How Security Is Embedded in Optra Delivery

Security is integrated into day-to-day engineering and release workflows:

  1. Code is scanned continuously and at key SSDL checkpoints.
  2. Platform and service security posture is reviewed and improved iteratively.
  3. Logs are centralized for both enterprise SOC workflows and Optra support needs.
  4. Threat models are reviewed and updated to reflect architecture and risk changes.
  5. Upgrades are treated as standard operations, not one-time tasks.

Summary

Optra security combines proactive tooling, centralized monitoring, and a practical hardening roadmap. The platform maintains strong dependency and language hygiene today while actively advancing Kubernetes, container, and service hardening to further strengthen security posture.