Integrations
Microsoft Azure
How Telonic runs inside your own Microsoft Azure subscription, with every component in your environment and your own encryption keys.
On this page
If your security policy requires customer data to stay in infrastructure your organisation controls, Telonic can be deployed into your own Microsoft Azure subscription (the unit in which Azure organises your resources, billing and access). Every Telonic component runs inside your environment, in the Azure region you choose, and stored data can be encrypted with keys you manage. Only operational health signals, which contain no customer data, are sent to Telonic, and you can switch them off. Your organisation owns the subscription; Telonic deploys and runs the software in it.
What running in your own Azure subscription means
| Aspect | How it works |
|---|---|
| Where it runs | Every Telonic component runs inside your Azure subscription, in the Azure region you choose. The region is recorded in your agreement |
| Where processing happens | All processing for your deployment runs in the region you choose, unless you explicitly choose a language model provider outside it |
| Encryption | Connections use TLS (Transport Layer Security, the standard encryption for data in transit) version 1.2 or higher. Stored data is encrypted with AES-256 (the Advanced Encryption Standard, using 256-bit keys) |
| Your keys | You can use customer-managed keys (encryption keys your organisation creates and controls) held in Azure Key Vault, Azure's key management service |
| What reaches Telonic | Operational health signals only, containing no customer data. You can switch them off |
| Backups | Backups and disaster recovery copies are encrypted and stay in the same country as your deployment |
How it connects
Your cloud team provides the subscription, or a part of one set aside for Telonic, and grants the access described below. Telonic deploys and runs the software there, and the computing capacity your deployment needs is sized with your team during implementation. Your agents connect to your other systems from inside your own environment, over routes your network team controls.
Telonic engineers reach your deployment only when you approve it. Access is limited to named engineers, working from the UAE or your chosen country, and is time-limited and logged. If you later decide to move to another hosting option, the move is carried out as a migration agreed with you in advance: data is moved encrypted and never leaves the countries your agreement permits.
Telonic's own UAE and Saudi Arabian hosting options also use major cloud providers' data centres in those countries. For those options, the provider and region are named in your agreement. See Hosting and data residency.
Permissions
| Permission | Needed for | Default |
|---|---|---|
| Deploy and update Telonic components in the resources set aside for them | Installing, updating and supporting your deployment | Each access needs your approval, and is time-limited and logged |
| Use of your encryption keys | Encrypting stored data | Only if you choose customer-managed keys |
| Send operational health signals to Telonic | Monitoring the health of your deployment | On. You can switch it off |
| Access to other resources in your subscription | Not needed | Not requested |
Telonic can only reach what you have granted, and only when you approve it.
In practice
Wadi Assurance, an insurer, runs its core systems on Azure and requires customer data to stay in its own subscription.
- Its cloud team sets aside resources in the insurer's subscription, in its chosen region, and grants Telonic deployment access for the installation window.
- Telonic deploys the agent and connects it to the insurer's claims system inside the same environment.
- The security team configures customer-managed keys in Azure Key Vault and reviews the operational health signals before leaving them switched on.
- For each later update, the insurer approves the access, and every session is logged.
What your team controls
- The subscription, region and network routes.
- The encryption keys, and whether to use them.
- Whether operational health signals are sent, and each approval of engineer access.
Related
- Cloud hostingIntegrations
- Hosting and data residencySecurity and data protection
- EncryptionSecurity and data protection
- Access control and single sign-onSecurity and data protection
- What we need from your IT teamIntegrations
Product names and logos are trademarks of their owners. Their mention shows systems Telonic connects to and does not imply partnership or endorsement.