Security

Flow diagram

Astry is non-intrusive by design and follows a push pattern: your systems push data to Astry, never the other way around.

Astry is a non-intrusive tool by design: you don't need to install it on your information system, nor grant it access to all of your data or metrics. It was designed so that you keep control over the data it has access to, in particular by adopting a push pattern (as opposed to the pull approach offered by other solutions): it is the applications or solutions deployed on your systems that proactively, explicitly, and configurably push certain metrics or alerts to Astry.

The image below illustrates this design model:

  • on the left is your information system, which pushes data in an encrypted and authenticated way (generally via an API key) through the integrations we offer
  • in the center is the Astry tool, which handles incident tracking, resolution, team management, on-call schedule configuration, incident deduplication, and more
  • on the right are the tool's users, who can be alerted in different ways when an incident occurs, and who can view and act on incidents

Your information system

NagiosPrometheusElasticsearchZabbixGrafanaEmailWebhook
HTTPSAPI-KEY

ASTRY

Gestion d'incidents

Astreintes & routage

Déduplication

PUSH

Utilisateurs

SMS
Téléphone
Email
Teams
Push notifications
WhatsApp

Note: All exchanges are secured through the use of encrypted channels (usually HTTPS) and authentication.

Detailed view

The image below describes a more detailed view of the system and its flows, in particular:

  • interactions between information systems (including those of our providers, depending on the type of exchange (alerts, notifications, incident actions, ...))
  • some essential components within our information system

Detailed view of the Astry system