Encryption

All TrafficPeak network communication uses TLS encryption. The cloud provider’s object storage encryption handles encryption-at-rest concerns.

This simplified diagram of Hydrolix architecture shows TLS-encrypted connections and storage encryption.

TrafficPeak Encryption Diagram

Data ingestion

Akamai DataStream 2 streams are pushed to the TrafficPeak instance using the HTTPS Intake API. Akamai SIEM data is polled via HTTPS through the Hydrolix SIEM Pull mechanism.

Management

Management of the TrafficPeak software is performed using the HTTPS Hydrolix Configuration API, which uses TLS. The Kubernetes API allows management of the Kubernetes software using industry-standard tools which communicate using over TLS .

Query

Visualization tools such as Grafana provide customer dashboards by querying Hydrolix through the Hydrolix Query API over TLS. Customer access to Grafana has HTTPS/TLS turned on by default.

Object storage

The file system for TrafficPeak is implemented using the cloud provider’s object storage, which communicates over TLS for security. When at rest, data is stored in encrypted volumes in object storage.