Controls
How we secure the way we build and run the OXU Platform, and the security features the platform gives customers. Controls that map to ISO/IEC 27001:2022 Annex A show the reference; they will be independently assessed in the certification audit.
Governance
Dedicated information security function
A Security Manager leads our information security management system (ISMS), including risk management and compliance.
ISO/IEC 27001 Annex A mapped
Each of the 93 controls in ISO/IEC 27001:2022 Annex A is mapped to the policy, standard or procedure that will address it.
Audited cloud infrastructure provider
Production runs on Amazon Web Services, whose data centres operate independently audited physical and environmental security controls.
Access to production
Single sign-on with multi-factor authentication
Staff sign in to our cloud accounts and internal systems through single sign-on, with multi-factor authentication required.
Production hosts reached only through a gateway
Access to production hosts goes through a VPN and a privileged access management gateway, never directly from the internet.
No direct database access for developers
Developers have no direct access to production databases. Changes to production data are requested through tickets and carried out by the infrastructure team.
Infrastructure and operations
Separated environments
Development, staging, sandbox and production are separate environments, and production has its own infrastructure repositories.
Infrastructure defined as code
Cloud infrastructure is defined as code and deployed through automated pipelines, so every change is versioned and reviewable.
Segmented production network
The production network is divided into public, private and isolated subnets, so internal services are not exposed to the internet.
Encryption in transit
Connections to the OXU Platform are encrypted with TLS at AWS load balancers, using certificates that renew automatically.
Centralized monitoring and alerting
Metrics, logs and traces from production are collected centrally, and alerts are routed to dedicated production channels.
Single hosting region
The OXU Platform runs in the AWS Singapore region (ap-southeast-1).
Product security
Multi-factor authentication for customer accounts
OXU Identity supports multi-factor authentication with:
- authenticator apps (TOTP)
- passkeys (FIDO2 / WebAuthn)
Standards-based single sign-on
OXU Identity signs users in to connected applications with OpenID Connect and OAuth 2.0, and with SAML 2.0.
End-to-end encrypted files in OXU Drive
OXU Drive encrypts every file on the device before it is uploaded: the contents with AES-256-GCM and the file name with AES-SIV. Our servers cannot read a file without its key.
Recovery keys for encrypted files
OXU Drive users can save a recovery key, for example as a PDF, and organization administrators can restore a member’s access to their encrypted files.
Encrypted notes with post-quantum key exchange
OXU Notes encrypts notes on the device with AES-256-GCM. It exchanges keys with ML-KEM-768, a post-quantum algorithm, derives keys from passwords with Argon2id, and signs data with Ed25519.
Key management with standard algorithms
OXU KMS manages symmetric keys (AES-256-GCM, ChaCha20-Poly1305) and asymmetric keys (RSA 2048, 3072 and 4096; elliptic curves P-256, P-384 and P-521).
Audit log of key operations
OXU KMS records sensitive key operations, such as creating, rotating and disabling keys and wrapping or unwrapping data, for each organization and workspace. Organization administrators can review the log and forward events to OXU Guard.
Google Workspace client-side encryption
OXU KMS can act as the external key service for Google Workspace client-side encryption, so the organization, not Google, holds the keys.
Device trust
OXU Access enrolls devices and checks their security posture before they are trusted.