Security

Security that stands up to scrutiny

obserae is built to observe your network without becoming another source of exposure. It runs on your infrastructure, keeps your data under your control, and turns its most important security claims into checks your team can perform.

The security posture, at a glance

Six deliberate choices keep control with your organisation.

  • Self-hosted by design
  • No telemetry or vendor cloud
  • Passive, agentless collection
  • Signed, attestable releases
  • Your identity provider and roles
  • Verifiable audit and recovery

Six questions worth asking

Clear answers for a security review — with enough detail to verify them.

Data Community

Who controls the data?

You do. Flow records, sessions, cartography and alerts remain on the infrastructure you operate. Spartan Conseil has no access to the instance or its data.

Availability Community

Can it affect production traffic?

No. obserae reads exported flow records away from the traffic path. If the service stops, you lose visibility for that period — not connectivity.

Network Community

Does it need Internet access?

No. There is no telemetry, activation or online licence check. Optional enrichments and outputs are explicit, controlled by you, and can be disabled for an air-gapped deployment.

Supply chain Community

How do we trust a closed-source release?

Verify it before deployment. Every release is signed and accompanied by a software inventory and build provenance that your team can check offline.

Access Business and above

How is access governed?

Use named accounts, granular roles, OIDC or Active Directory, and two-factor authentication for local users. A local break-glass administrator remains available.

Assurance Business and above

Can we prove what happened?

A tamper-evident audit trail records operator actions across the interface and command line. Its integrity can be verified independently from the raw files.

Community free and self-hosted  ·  Business and above the complete commercial feature set, priced by organisation size

The core security posture is the same in every edition. Self-hosting, no telemetry, controlled egress, passive collection, signed releases, encrypted secrets, backups and responsible disclosure are not paid security upgrades. Every commercial edition adds the same identity, audit and SOC capabilities; only the organisation-size band changes. See the full split on the pricing page.

Your data stays under your control

obserae runs entirely on infrastructure you operate. Flow records, sessions, cartography, rules and alerts remain there; there is no vendor cloud in the data path and Spartan Conseil has no remote access to the instance.

The product analyses network metadata — who communicated with whom, when, over which protocol and in what volume. It does not capture packet payloads or become a repository for users’ content. Your retention policy, storage location and access controls remain yours.

For normal self-hosted operation, this also keeps the supplier review simple: Spartan Conseil does not receive or process your instance data on your behalf. Any external destination you choose for an alert or backup remains visible and under your control.

It observes without sitting in the way

Routers, firewalls and switches export standard NetFlow or IPFIX records; obserae reads a copy away from the traffic path. It does not proxy, filter or block production communications. If it stops, the network continues to operate — visibility is interrupted, connectivity is not.

There is no obserae agent to deploy across servers and workstations. Where additional east-west visibility is needed, a standard probe or mirror port can provide it without introducing proprietary code on the systems being observed.

The deployment is deliberately compact: one host and plain files on disk, without a mandatory cluster, message broker or external search stack. Fewer moving parts mean less infrastructure to expose, patch and recover.

No telemetry, controlled egress

obserae sends no usage telemetry to Spartan Conseil. There is no account to create, no activation service, no online licence check and no remote kill switch. Commercial licences are local files, validated by the instance itself.

Optional outbound connections are easy to account for:

  • public threat-intelligence and cloud-provider lists can be downloaded for enrichment;
  • alerts can be sent to destinations you configure;
  • backups can be copied to storage you select;
  • sign-in can use your identity provider.

These connections are configured by you, and enrichments can be disabled. With no external destinations or identity provider configured, obserae supports fully isolated, air-gapped operation; the product manual is included locally.

User-supplied outbound destinations also pass through an egress guard. Internal, loopback, link-local and cloud-metadata addresses are refused by default, including after DNS resolution. Legitimate internal destinations must be explicitly allowed.

Trust the evidence, not the claim

obserae is closed source, so each release is designed to be verified before it is trusted.

Every binary and container release is protected by a keyless Sigstore signature recorded in a public transparency log. It also ships with:

  • an SBOM, the inventory your team can scan for known vulnerable dependencies;
  • SLSA build provenance, which identifies the source commit and release workflow that produced the artefact;
  • checksums for integrity verification.

The signature and provenance can be checked offline against the downloaded files before installation. The installer always verifies the checksum; it can also require a valid signature and verify the build provenance. The complete procedure is documented in Verify a Release.

Qualified security reviewers can also inspect the source code under NDA. Closed source does not mean closed to scrutiny.

Access fits your organisation

Business and above named accounts, roles, two-factor authentication, OIDC / SSO and Active Directory

obserae integrates with Microsoft Entra ID, Keycloak, Authentik, Google Workspace and Active Directory. Groups in your directory map to roles in obserae and are refreshed at sign-in, so access follows the identity lifecycle you already manage.

Permissions are enforced by the server, not merely hidden in the interface. Built-in roles cover administration, investigation, read-only audit and monitoring; custom roles and per-user API tokens support least-privilege access. Local accounts support two-factor authentication, while SSO users inherit the authentication policy of their identity provider.

The built-in administrator remains local as a break-glass account if the identity provider is unavailable. Login rate limits and network restrictions add another layer around interactive access, and the web interface sits behind your own reverse proxy and TLS policy.

Actions leave verifiable evidence

Business and above available to every edition free of charge during the beta

The audit log records operator actions from both the web interface and the local command line: authentication events, changes to users and permissions, rules, cartography, outputs, connectors and recovery operations.

The journal is tamper-evident. Entries are chained with SHA-256 hashes and closed files are sealed with an HMAC, so editing, deleting or reordering recorded history produces a detectable break. The chain can be verified offline from the raw files, independently of the running service.

This provides understandable evidence for an internal investigation, a change review or control frameworks such as ISO 27001, NIS2, DORA and SOC 2. It does not claim compliance on your behalf; it gives your team evidence it can inspect and retain.

Recovery is designed in

Built-in backups capture the state needed to rebuild an instance: configuration, cartography, detection rules, users, retained history, enrichment state and the audit trail. Independent backup processes can follow different schedules and retention policies, with local, S3-compatible and SFTP destinations under your control.

Point-in-time recovery can be previewed before it is applied. An uploaded archive and its matching master key are validated before working data is replaced, reducing the risk of a partial or mistaken restore.

The master key protects stored credentials and audit-log seals. Keep a copy in your secret manager, separate from the instance: with it and a valid backup, rebuilding from bare metal is a controlled procedure.

A clear vulnerability process

Security reports go directly to security@spartan-conseil.fr. Our published policy targets acknowledgement within five business days, followed by an assessment of severity, affected versions and reproducibility, then coordinated disclosure and status updates.

Good-faith research performed within the policy is authorised in writing and covered by a safe harbour. Security fixes are released on the current version, and the disclosure process applies to every edition. Read the full security policy.

Your security team is welcome to look closer.

We answer architecture questions, support qualified source reviews under NDA, and handle vulnerability reports directly.