Obsidian™ Security¶
Pattern Matched Technologies™ takes the greatest of care to verify and validate that the PMT™ Service Connectivity Platform implements the stringiest of security measures to protect not only the end-to-end solution and customer services enabled through the Gateway, but also to protect any personal information captured or configured and processed by the Gateway for these services.
No transmitted data interrogation is done by the PMT™ Service Connectivity Platform during the processing of received traffic, service configuration matching or capturing of analytical information for reporting and billing purposes.
Compliance¶
By utilising AWS, Obsidian™ inherits all the compliance and security controls implemented by AWS and would match the same as any customer who is already running in AWS for their Service or API enabled through the Gateway.
Security standards and compliance certifications are inherited from AWS, including, but not limited to, PCI-DSS, HIPAA/HITECH, FedRAMP, GDPR, FIPS 140-2, and NIST 800-171.
Links to information related to compliance:
- Amazon Web Services - Compliance
- Amazon Web Services - Compliance Resources
- Amazon Web Services - Security
- Amazon Web Services - Compliance Reports
Secure End-to-End¶
All connections and data processed by the Gateway remains encrypted throughout the processing flow by supporting only the latest TLS specifications v1.2 and v1.3 for secure connection establishment. SSL certificates are served at the edge for client connections to the PMT™ Service Connectivity Platform and if required, client-side verification and handshaking to further validate the secure connection from the PMT™ Service Connectivity Platform to the provisioned Service or API.
Only administrators on the platform will be able to manage SSL certificates and keys and this functionality is not accessible to normal users to inspect or capture information for other purposes.
Access Control and Least Priviledge¶
The PMT™ Service Connectivity Platform solution leverages various aspects of role-based access control (RBAC) to manage access to functionality in the online portal and inside the infrastructure where the components are deployed. Further to this access is also managed by ensuring minimal access (Principal of Least Privileged) to areas and functionality required by system maintainers and support staff.
The Obsidian™ Portal access is configured by the administrative user on the portal. Users are created as either administrative or normal users, with normal user access determined by setting up specific role-based access to features and functions on the portal.
Infrastructure Security¶
By leveraging various security elements of AWS and employing the principle of shared responsibility, Pattern Matched Technologies™ and the PMT™ Service Connectivity Platform can verify and protect the infrastructure utilised by the PMT™ Service Connectivity Platform components.
By making use of services like AWS Shield and AWS Web Application Firewall (WAF), the PMT™ Service Connectivity Platform is protected against fraudulent DDoS and hacking attacks, and further protecting the services enabled through the PMT™ Service Connectivity Platform.
Secure Customer Routing¶
Additional security measures applied to traffic received and processed by the PMT™ Service Connectivity Platform for Services and APIs enabled through the Gateway, direct peering connections are supported inside the AWS network to leverage private links or direct VPC peering to the customers’ network so that once traffic is received and processed, it does not have to leave the AWS network over the public internet to reach the final destination Service or API, but remains inside the private network for the remainder of the request/response flow.
This is dependent on the customers’ setup and ability to configure and will be analysed, architected, and implemented once
joint sign-off is received between parties.
This is only supported for implementations in AWS.