Security

Your data. Your account. Your control.

OBSESC is designed for environments with high security and compliance requirements. Your telemetry never leaves your AWS account.

SAME DATA.
MORE TIME.
UNDER YOUR CONTROL.
LOGS
METRICS
TRACES
EVENTS
...
NO VENDOR ACCESS.
NO DATA EXFILTRATION.
NO COMPROMISE.
OBSESC
Runs in your AWS account

No hosted control plane.
No access role for us.

You keep custody

Your bucket, your keys,
your network, your data.

We never see your data

We do not receive, store or process your telemetry.

Built for compliance

Designed to meet the requirements of security, legal and audit teams.

Security architecture

A clear security boundary.

OBSESC deploys entirely within your AWS account, alongside your existing observability stack. All data remains in your environment, under your control.

Your environment
Applications
Infrastructure
Security tools
AWS services
...
Logs, metrics, traces, events (OTel, Fluent Bit, Vector, etc.)
aws Your AWS account
Operator console |Explore |Query API
OBSESC node
OBSESC node
OBSESC node
+ n
Navigation tier (in your account)
Navigation tier (in your account)
Navigation tier (in your account)
Your object storage bucket (S3)|Fidelity tier
Every event, complete, in open columnar files under an open table format
Your tools / query engines
OBSESC Explore
Amazon Athena
Trino
Spark
DuckDB
Any engine that reads open formats
No inbound access

We have no access role, no management plane and no ability to access your account.

Encrypted with your keys

Data at rest is encrypted with your AWS KMS keys. TLS is supported on every listener.

Open formats

Your data is stored in open columnar formats, readable by your tools at any time.

Integrity verification (optional)

Optional cryptographic integrity checks, anchored to storage you control.

Compliance & governance

Designed to meet your requirements.

OBSESC is built with the needs of security, legal and compliance teams in mind.

Data residency
All data stays in your AWS account and region.
Access control
Uses your IAM, with optional sign-in through your OIDC identity provider.
Auditability
Access and activity records you can review.
Minimal data handling
We do not receive or process your telemetry.
Open and portable
Your data remains readable even if you stop using OBSESC.
Supports compliance
Helps you meet your obligations: data stays in your account, under your keys.
Read our compliance overview
Data custody

You retain full control.

Your data, your keys, your lifecycle.

1{ 2 "account": "your-aws-account", 3 "bucket": "your-s3-bucket", 4 "encryption": "your-kms-keys", 5 "access": "no-vendor-access", 6 "data": "never-leaves-your-account", 7 "format": "open-columnar", 8 "retention": "as-long-as-you-need", 9 "control": "yours" 10}

Your data stays in your environment. Always.

Security deep dive

Read the full security documentation.

Security model, encryption, access control, networking and compliance.

View security docs