
Monitoring → Observability
Regulated environments buy evidence, not dashboards. What actually changes when monitoring becomes observability — and what a FINMA audit asks for.

Regulated environments buy evidence, not dashboards. What actually changes when monitoring becomes observability — and what a FINMA audit asks for.

Pod logs carry PII, namespaces are tenants, and the audit log is evidence. What changes when a cluster's telemetry has to survive a FINMA or ISO review.

Data residency is not sovereignty. Who can compel access to your telemetry, who operates the control plane, and how to keep the answer yours.

A reference architecture for telemetry under revDSG and FINMA: classify at the edge, a Swiss gateway tier, split destinations, a control plane you host.

PII and client-identifying data are different legal categories. No scanner reliably finds the second — classify before data leaves the network.

Keep credentials out of committed Collector config: env vars, file substitution, Kubernetes Secrets, Vault — and how to rotate without downtime.

Mask PII in-pipeline before telemetry crosses your network boundary — attribute deletion, regex masking, and hashing that preserves correlation.