Clophi integrates natively with your Azure environment — respecting your identity model, operating on dedicated infrastructure. Built for organizations where security and compliance are non-negotiable.
Every layer of Clophi's architecture is designed to meet the security, compliance, and data residency requirements of enterprise organizations.
Native Microsoft Entra ID integration with one-to-one RBAC permission mapping against your Azure environment.
Your organization runs on an isolated cluster in your chosen Azure Region — meeting data residency and compliance requirements.
Clophi operates through a Service Principal with scoped Reader permissions. You control visibility from Tenant level down to Resource Groups.
Sensitive deployment operations run within your own tenant via self-hosted extensions. Secrets never leave your security perimeter.
Access the platform entirely through your internal network via VPN — bypassing the public internet endpoint for maximum isolation.
Comprehensive audit trails with encrypted retention. Export logs to your SIEM or external auditing tools for full transparency.
Clophi is built on a foundation of Identity-driven security, integrating natively with Microsoft Entra ID (Azure AD). The platform strictly adheres to your organization's established Role-Based Access Control (RBAC) assignments.
Every action performed by a user within Clophi, whether viewing resources or contributing changes, is directly governed by the specific roles and permissions assigned to that user in Azure. Clophi maintains one-to-one permission mapping against the role assignments (RBAC) of your organization's Azure environment.
Clophi operates on a dedicated cluster provisioned exclusively for your organization. To ensure adherence to your regional data and security compliance measures, you can select the specific Azure Region where your environment is hosted.
Clophi operates through a Service Principal with scoped Reader permissions . You maintain full control over visibility, from the entire Tenant level down to specific Resource Groups.
For deployment-related processes and sensitive operations, self-hosted extensions run within your own tenant. Your deployment logic and secrets never leave your security perimeter.
Access the platform entirely through your internal network via VPN, bypassing Clophi's public internet endpoint for maximum isolation.
Clophi maintains comprehensive audit trails, tracking and logging every user action within the platform — supporting your internal governance, regulatory, and compliance requirements.
Apart from Clophi’s internal activity logs, you have the option to stream Azure-based insights—such as drift detection details—to external auditing tools, providing total transparency across your cloud operations.
All logs are stored in an encrypted format for a default period of 9 weeks, ensuring a clear historical record of environment changes.
Logs can be easily exported for integration with your existing Security & Compliance partners, such as SIEM (Security Information and Event Management) or external auditing tools.