Should the collector run on Sopht stack or on your stack?
By default, we advise to run it on Sopht stack. That way we are in charge of the monitoring, alerting, we can update the collectors more easily…
The client can choose to run it on its stack. The main reasons are:
- if the software can only be accessed via a restricted Network (local, private, though IP filtering…)
- if there are confidential data that the client want to anonymize before they reach Sopht’s stack
- if the client’s prefer to handle secrets on their side, without communicated them to Sopht.
The consequences are :
- client handles the infra: container deployment, monitoring, debugging
- client needs to update the collector to new versions when asked by Sopht, for instance for security or functional updates.

Retrieval on Sopht Stack
Retrieval on customer’s side