Skip to content
Oten website (opens in a new tab)Oten Trust Center

Oten Switzerland GmbH

Oten Switzerland GmbH is a global security SaaS company. Through the OXU Platform, we help organizations manage digital identities, control encryption keys and protect collaboration across distributed teams. Our Trust Center brings together the security controls, compliance progress and information you need to evaluate Oten as your technology partner.

Controls

How we secure the way we build and run the OXU Platform, and the security features the platform gives customers. Controls that map to ISO/IEC 27001:2022 Annex A show the reference; they will be independently assessed in the certification audit.

Governance

  • Dedicated information security function

    A Security Manager leads our information security management system (ISMS), including risk management and compliance.

    • ISO 27001 A.5.2
  • ISO/IEC 27001 Annex A mapped

    Each of the 93 controls in ISO/IEC 27001:2022 Annex A is mapped to the policy, standard or procedure that will address it.

    • ISO 27001 cl. 6.1.3
  • Audited cloud infrastructure provider

    Production runs on Amazon Web Services, whose data centres operate independently audited physical and environmental security controls.

    • ISO 27001 A.5.23
    • ISO 27001 A.7.1

Access to production

  • Single sign-on with multi-factor authentication

    Staff sign in to our cloud accounts and internal systems through single sign-on, with multi-factor authentication required.

    • ISO 27001 A.8.5
  • Production hosts reached only through a gateway

    Access to production hosts goes through a VPN and a privileged access management gateway, never directly from the internet.

    • ISO 27001 A.8.2
    • ISO 27001 A.8.18
  • No direct database access for developers

    Developers have no direct access to production databases. Changes to production data are requested through tickets and carried out by the infrastructure team.

    • ISO 27001 A.8.3
    • ISO 27001 A.8.32

Infrastructure and operations

  • Separated environments

    Development, staging, sandbox and production are separate environments, and production has its own infrastructure repositories.

    • ISO 27001 A.8.31
  • Infrastructure defined as code

    Cloud infrastructure is defined as code and deployed through automated pipelines, so every change is versioned and reviewable.

    • ISO 27001 A.8.9
  • Segmented production network

    The production network is divided into public, private and isolated subnets, so internal services are not exposed to the internet.

    • ISO 27001 A.8.20
    • ISO 27001 A.8.22
  • Encryption in transit

    Connections to the OXU Platform are encrypted with TLS at AWS load balancers, using certificates that renew automatically.

    • ISO 27001 A.8.24
  • Centralized monitoring and alerting

    Metrics, logs and traces from production are collected centrally, and alerts are routed to dedicated production channels.

    • ISO 27001 A.8.15
    • ISO 27001 A.8.16
  • Single hosting region

    The OXU Platform runs in the AWS Singapore region (ap-southeast-1).

Product security

  • Multi-factor authentication for customer accounts

    OXU Identity supports multi-factor authentication with:

    • authenticator apps (TOTP)
    • passkeys (FIDO2 / WebAuthn)
  • Standards-based single sign-on

    OXU Identity signs users in to connected applications with OpenID Connect and OAuth 2.0, and with SAML 2.0.

  • End-to-end encrypted files in OXU Drive

    OXU Drive encrypts every file on the device before it is uploaded: the contents with AES-256-GCM and the file name with AES-SIV. Our servers cannot read a file without its key.

  • Recovery keys for encrypted files

    OXU Drive users can save a recovery key, for example as a PDF, and organization administrators can restore a member’s access to their encrypted files.

  • Encrypted notes with post-quantum key exchange

    OXU Notes encrypts notes on the device with AES-256-GCM. It exchanges keys with ML-KEM-768, a post-quantum algorithm, derives keys from passwords with Argon2id, and signs data with Ed25519.

  • Key management with standard algorithms

    OXU KMS manages symmetric keys (AES-256-GCM, ChaCha20-Poly1305) and asymmetric keys (RSA 2048, 3072 and 4096; elliptic curves P-256, P-384 and P-521).

  • Audit log of key operations

    OXU KMS records sensitive key operations, such as creating, rotating and disabling keys and wrapping or unwrapping data, for each organization and workspace. Organization administrators can review the log and forward events to OXU Guard.

  • Google Workspace client-side encryption

    OXU KMS can act as the external key service for Google Workspace client-side encryption, so the organization, not Google, holds the keys.

  • Device trust

    OXU Access enrolls devices and checks their security posture before they are trusted.