Security

Tenant isolation, RBAC, and NDR on the same control plane.

Optima Pulse is built for enterprise operational trust: least-privilege access, server-side tenancy, auditable automation, and network detection that stays bound to evidence.

Optima Pulse
Optima Pulse NDR security workspace
NDR detections, hunting, evidence, and response — with tenant RLS on every object.

Platform security

RBAC

Permissions such as devices:write, ndr:investigate, automation:execute, and admin:* map to routes and actions. Empty navigation groups are dropped.

Tenant isolation

FORCE RLS on operational tables. Tenant context is never accepted from the client.

Edge trust

Collectors authenticate to the control plane. Telemetry ingest is not an anonymous UDP hole into the API.

Encryption

mTLS on collector paths and TLS on operator access. Sensitive operational flows stay on modern transport security.

Audit

Administration and automation execution history support change accountability across tenants.

SSO

OIDC via Keycloak for enterprise identity, or local auth for lab and air-gapped installs.

Network detection

Explainable detections

Risk factors, fingerprints, occurrence counts, and evidence references — not a black-box severity number.

Honest empty states

No threat-intel feed configured stays visible. Insufficient graph evidence is stated, not drawn as a fake attack path.

Response with control

NDR response uses automation execute permissions and approvals for actions that change the network.

Next step

Design a secure deployment model

Request a Demo