Security and privacy, built in — not bolted on
Workforce data is among the most sensitive data a company holds. Workforce Observatory runs entirely inside your perimeter, with governance controls at every layer of the pipeline.

Your perimeter, your rules
- Deploys on-premises or in your private cloud — no runtime dependency on public networks
- Containerized stack; air-gap-capable delivery for restricted environments
- Your data never leaves your infrastructure; no vendor-side telemetry
Identity and access
- Corporate OIDC integration, with a path to ADFS/Keycloak federation against AD
- Role-based access — admin, analyst, viewer — with organization-level scopes
- Scopes enforced by the API on every query, not by UI visibility
- Row and column policies applied before any metric is computed

Governance by construction
- Every number carries lineage: source, extraction job, schema version, mapping version
- Bronze payloads are immutable and append-only; reprocessing is explicit and auditable
- Connector secrets are resolved server-side and never returned to the browser
- API audit events cover authentication, publishing and configuration changes
GDPR-conscious analytics
- Person identifiers are pseudonymized (HMAC) in Silver and Gold layers
- Sensitivity labels travel with fields through the catalog and mappings
- Aggregate-only analytics by default; no individual-level records in dashboards
- Retention and legal-hold workflows are first-class roadmap items
Frequently asked security questions
Where is our workforce data stored?
Inside your own infrastructure. The platform deploys as a containerized stack in your data center or private cloud, and operates without runtime dependencies on public networks. No data is sent to us or to any third party.
Can individual employees be identified in dashboards?
No. Person identifiers are pseudonymized during ingestion and dashboards expose only governed aggregates. Row, column and organization-scope policies are enforced by the API on every query.
How does it integrate with our identity provider?
Through corporate OIDC — the standard path to Microsoft Entra ID, ADFS or Keycloak federation with Active Directory. Roles and organization scopes map from your existing groups.
What happens to our data if we stop using the platform?
Everything lives in open formats in your storage — Parquet tables and versioned specifications you own. There is no proprietary lock-in: your governed data remains readable without the platform.
Want the architecture walkthrough?
We will go through the deployment model, identity boundary and data flows with your security team.