Articles in this section

Secure Deployment Guidance for Bold BI in Organization-Managed Cloud Environments

Published:

Overview

Bold BI is designed to support secure deployments across cloud, on-premises, and hybrid environments.

Bold BI has successfully completed a SOC 2 audit covering the application and the controls implemented within the managed Bold BI Cloud environment. Additional information regarding Bold BI’s security and compliance posture is available at:

When Bold BI is deployed in an organization-managed cloud or on-premises environment, the same application-level security capabilities are available. However, the organization deploying and managing Bold BI is responsible for implementing and maintaining appropriate security controls for the underlying infrastructure.

This may include:

  • Network security and firewall management
  • Reverse Proxy and Web Application Firewall (WAF) configurations
  • HTTPS/TLS implementation and certificate management
  • Identity and access management
  • Infrastructure hardening
  • Security monitoring and logging
  • Vulnerability management and patching
  • Regular security reviews and audits

Enterprise Reverse Proxy Architecture

Enterprise Reverse Proxy Architecture for Embedded Analytics.png

The Enterprise Reverse Proxy Architecture provides a secure deployment model in which internet traffic is routed through a Reverse Proxy or Web Application Firewall (WAF) before reaching internal application resources.

Key Benefits

  • Secure SSL/TLS termination
  • Traffic filtering and inspection
  • Protection against common web-based threats
  • Request routing and load balancing
  • Isolation of internal resources from direct internet exposure
  • Scalability and high availability options

This architecture is commonly adopted in cloud and hybrid environments where organizations require strong perimeter security while maintaining deployment simplicity.


Enterprise DMZ Architecture

Enterprise DMZ Architecture for Embedded Analytics.png

The Enterprise DMZ Architecture provides an additional security layer through network segmentation and controlled access between internet-facing and internal resources.

Key Benefits

  • External and internal firewall protection
  • Dedicated DMZ for public-facing components
  • Reverse Proxy/WAF protection within the DMZ
  • Controlled communication between security zones
  • Additional isolation of Bold BI servers, the metadata database, and business data sources
  • Enhanced support for security and compliance requirements

This architecture is well suited for organizations requiring stricter security controls, network segmentation, and defense-in-depth strategies.


Security Considerations

Bold BI provides application-level security features regardless of the deployment environment.

For deployments hosted within an organization-managed cloud or on-premises environment, the organization is responsible for implementing and maintaining the security controls of the supporting infrastructure, including:

  • Cloud platform security
  • Network architecture and segmentation
  • Firewall and WAF configuration
  • HTTPS/TLS implementation and certificate management
  • Operating system and server hardening
  • Monitoring and logging
  • Vulnerability management and patching
  • Security reviews and compliance assessments

Organizations should evaluate and implement these controls based on their internal security policies, compliance requirements, and risk management practices.


Recommendations

To strengthen the security posture of a Bold BI deployment, organizations should consider:

  • Deploying Bold BI behind a Reverse Proxy or Web Application Firewall (WAF)
  • Implementing appropriate network segmentation and firewall controls
  • Enforcing HTTPS/TLS for all communications
  • Following infrastructure hardening best practices
  • Conducting regular vulnerability assessments and security reviews
  • Reviewing access controls and monitoring security-related events

The reference architectures included in this article illustrate commonly adopted deployment patterns and can be adapted to align with specific security, compliance, and operational requirements.

Note: The architectures shown above are reference deployment patterns intended to illustrate common security best practices. Organizations should adapt these patterns to align with their internal security policies, compliance requirements, and cloud architecture standards.


Conclusion

Bold BI provides a secure analytics platform with robust application-level security capabilities. Bold BI has successfully completed a SOC 2 audit covering the application and the controls implemented within the managed Bold BI Cloud environment.

When deploying Bold BI within an organization-managed cloud or on-premises environment, the organization remains responsible for securing the underlying infrastructure and ensuring that appropriate security and compliance controls are implemented and maintained.

The reference architectures provided in this article illustrate common deployment patterns that can help organizations design a secure Bold BI deployment.

For additional information regarding Bold BI’s security and compliance practices, refer to:

Was this article useful?
Like
Dislike
Help us improve this page
Please provide feedback or comments
LS
Written by Lingaraj Subramanian
Updated:
Comments (0)
Access denied
Access denied