SOC 2 Type I CertifiedSOC 2 Type II Certified

Compliance and Independent Assurance

Aravolta undergoes regular third-party assessments to validate the design and operating effectiveness of its security controls. Detailed audit reports, policies, and control evidence are maintained in Aravolta's trust portal and are available to customers and partners under NDA.

  • SOC 2 Type II (current)
  • Additional compliance initiatives tracked and managed through Aravolta's trust portal

For list of audited security controls Aravolta has implemented:
https://trust.delve.co/centralaxis/controls

For list of audited compliance reports:
https://trust.delve.co/centralaxis


Aravolta Platform Overview

Aravolta is an asset-level telemetry collection and normalization platform designed to operate alongside existing infrastructure systems or serve as a primary system of record. The platform collects telemetry from infrastructure assets in both whitespace and greyspace, including power, cooling, and server hardware. This data is exposed through a centralized asset API. Aravolta also includes an optional Data Center Infrastructure Management (DCIM) visualization layer.

The platform consists of two primary components:

  • A collector agent deployed within the customer environment
  • A cloud-based normalization, storage, API, and visualization layer

All active data collection occurs within the customer environment. Aggregation, normalization, analytics, alerting, and integrations are handled in the cloud.


Aravolta Collector Node

Deployment Model

The Aravolta collector is deployed within the customer's environment and may run as a physical node or, where preferred, a customer-managed virtual machine. In both cases, the same collector software is used and the runtime behavior is identical.

The collector is intentionally designed as a single-purpose service with no inbound management surface. Customers retain full control over where the collector runs and may disable or remove it at any time, at which point telemetry collection from that environment will cease.

The collector software is versioned and updated through a controlled release process. Updates may be applied by the customer or automatically, depending on deployment preferences. Update behavior is designed to be non-disruptive and does not require inbound access or manual intervention.

Key deployment characteristics:

  • Single-purpose collector process
  • No inbound network services
  • No SSH or remote shell access
  • Customer-controlled lifecycle (deploy, pause, remove)


Device Communication and Protocol Support

Aravolta is designed to integrate with a wide range of infrastructure devices and management systems commonly found in data center and facilities environments. The platform supports both standardized industry protocols and system-level integrations, allowing it to operate across heterogeneous infrastructure without introducing vendor lock-in.

The platform can communicate directly with infrastructure devices, intermediary management systems, or centralized control platforms, depending on deployment architecture and access patterns.

Supported communication methods and integration surfaces include:

  • Standard infrastructure protocols such as SNMP, Modbus, Redfish, IPMI, iDRAC, BACnet, etc
  • Direct integrations with data center and facilities management systems, including DCIM, EPMS, DCS, and BMS platforms
  • Custom protocol adapters and vendor-specific interfaces for specialized or proprietary hardware

Telemetry is collected using a poll-based model initiated by the Aravolta collector. Polling frequency is configurable and determined based on device capabilities, protocol constraints, and operational considerations. In environments with existing polling systems, Aravolta is designed to align with established limits to avoid contention or performance impact on upstream devices.

Security characteristics:

  • Poll-based, outbound-initiated data collection
  • Read-only access to devices and systems
  • No configuration changes, control operations, or actuation
  • No firmware updates or write operations performed by the platform


Authentication and Access Control

Each collector deployment authenticates to the Aravolta cloud platform using a unique, customer-scoped token. Tokens can be rotated or revoked at any time and are scoped to specific environments or sites. If a token is revoked, the associated collector is unable to authenticate and telemetry ingestion from that deployment ceases.

Authentication and access controls include:

  • Unique per-deployment authentication tokens
  • No hard-coded credentials

Data Handling and Privacy

Aravolta collects telemetry and asset metadata related to infrastructure monitoring and analytics. The platform does not collect customer application data or tenant workloads.

Data scope:

  • Infrastructure telemetry and asset metadata
  • No collection of end-user personal data
  • No application-layer or tenant workload data

Data handling characteristics:

  • Encryption of data in transit and at rest
  • Dedicated single-tenant database instance per customer; no shared database instances
  • Configurable data retention based on agreement

Customers retain ownership of all collected data.


Data Storage, Replication, and Backup

Telemetry from each customer is written directly to a dedicated, single-tenant time-series database instance. Instances are not shared between customers, and each instance runs in the cloud region agreed with the customer.

Storage and backup characteristics:

  • Dedicated single-tenant database instance per customer
  • Replicated storage within the hosting region
  • Scheduled backups of each instance, encrypted at rest
  • Multi-Availability-Zone deployment for platform services


Integrations and External Systems

Aravolta supports integrations with external systems for alerting, ticketing, analytics, and data export. Integrations are implemented through platform APIs and webhook-based events and operate entirely from the Aravolta cloud platform. No connectivity from external systems into customer data center networks is required.

Integration security characteristics:

  • Use of official APIs and webhook mechanisms provided by third-party systems
  • Token-based authentication scoped to individual integrations
  • Customer-controlled enablement, configuration, and disablement
  • No direct access to infrastructure devices or collector instances

Security Testing, Monitoring, and Assurance

Aravolta maintains an ongoing security assurance program designed to identify, assess, and remediate security risks across the platform.

Security assurance activities include:

  • Periodic external penetration testing conducted by independent third parties
  • Ongoing automated vulnerability scanning of infrastructure and applications
  • Formal tracking, prioritization, and remediation of identified high- and critical-severity findings
  • Centralized logging, monitoring, and alerting across cloud and platform components
  • Documented incident response and risk management processes

Learn More About Aravolta Security

Have questions about our security practices or need additional documentation for your security review? Our team is here to help.

Schedule a Security Review →