Third Party Index

Snapshot 20798

Document
Trust center
URL
https://otnos.com/security
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
118027 bytes
SHA-256 (raw)
fd62eeb7c654934b343043e500bd76b2fff22ed9956d93bc7baebf9abca8622b
SHA-256 (normalized text)
1f9bb33e06e0268ebe6ab672eb2dea03df9f756d1a65f16cb6956896bf7011c1

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Trust & Security
Security You Can Verify.
Data That Stays in the EU.
OTNOS is built for critical-infrastructure operators. We hold your data to the standard your own environment demands — encrypted, isolated per customer, and hosted in the European Union.
EU data residency · GDPR-aligned · Encrypted in transit and at rest
Where Your Data Lives
For European operators, data sovereignty is not a preference — it is a requirement. The core of your data never leaves the EU.
Application & database
Accounts, asset inventory, analysis results
🇪🇺 Germany
File & document storage
Uploads, reports, attachments
🇪🇺 EU region
Backups
Encrypted, automated daily
🇪🇺 EU region
Limited operational services
Authentication, billing, email delivery — minimal data
EU / US under DPF & SCCs
How We Protect It
Defense in depth across identity, network, application, and data — verified automatically on every release.
Encryption Everywhere
TLS in transit and encryption at rest for all stored data. Secrets and MFA seeds are encrypted with dedicated keys.
Strong Authentication
Multi-factor authentication and enterprise single sign-on (Microsoft Entra ID). Role-based access control throughout.
Strict Tenant Isolation
Every customer's data is segregated. Access is scoped to the owning organization on every request — verified by automated tests.
Hardened Edge
All traffic runs behind a CDN/WAF with DDoS protection. The origin accepts only authenticated edge traffic (mutual TLS).
Audit Logging
Security-relevant events (who, what, when, from where) are logged and retained for 365 days for full traceability.
Backup & Recovery
Automated daily backups with defined retention and a tested restore capability — kept in the EU.
Verified, Not Just Claimed
Every deployment runs an automated check that every API endpoint enforces authentication, plus continuous cross-tenant isolation testing. Security review is part of our development process, not an afterthought.
Data Protection & GDPR
OTNOS is EU-based and built around GDPR obligations. When you entrust us with your data, we act as your processor under a clear agreement — see our privacy notice for the full picture.
Data Processing Agreement based on the EU Standard Contractual Clauses, available for enterprise customers
Records of processing activities and a sub-processor list, provided on request
Data-subject requests handled within one month
Defined retention per data type, enforced automatically
Customer data deleted on request or at the end of the contract
Documented 72-hour breach-assessment and notification process
Retention at a Glance
Customer-uploaded contentControlled by you
Security audit logs365 days
Encrypted backups30 days rolling
Closed account dataDeleted within 90 days
Retention limits are enforced by automated jobs, not manual cleanup — deletion happens on schedule, every time.
Sub-Processors
We use a small, vetted set of service providers under contract. International transfers rely on the EU–US Data Privacy Framework and/or Standard Contractual Clauses. A named, current list is available to customers on request.
Category	Purpose	Location
Hosting & infrastructure	Application & database	🇪🇺 Germany
Cloud storage	Files, backups	🇪🇺 EU region
CDN / edge security	Traffic protection, DDoS mitigation	🇪🇺 EU edge
Identity / SSO	Authentication	EU / US · DPF
Payments	Billing	US · DPF
Email delivery	Notifications	US · DPF / SCCs
Compliance Status
We are honest about where we are. GDPR is a legal obligation we build around today; formal certifications are on a defined roadmap.
CSA STAR Level 1
Cloud Security Alliance registry · View our registry entry
Listed · Published CAIQ v4 self-assessment
GDPR
EU data protection law
Aligned · EU-hosted · DPA available
EU Data Residency
Data sovereignty for European operators
In place
ISO 27001
Information security management
ISMS implemented · Certification planned
What is CSA STAR?
The Cloud Security Alliance STAR Registry is the industry's public registry of cloud provider security posture. Providers answer the Consensus Assessments Initiative Questionnaire (CAIQ) — a standard set of questions mapped to the Cloud Controls Matrix, 197 control objectives across 17 domains, from encryption and access management to incident response and supply chain — and the completed questionnaire is published for anyone to read.
For you it replaces a security questionnaire you would otherwise have to send us: the answers are already written down, in a format your own security team already knows, hosted by a third party rather than by us.
Level 1 is a self-assessment, not an external audit. We publish it because the answers are specific and checkable, not because a third party has verified them — Level 2 requires an independent auditor and is a separate step. Read our full submission on CSA's own site: OTNOS in the STAR Registry.
GDPR is a law, not a certificate — there is no "GDPR badge." We demonstrate compliance through our practices, our DPA, and our documentation, all available for your review. We'd rather show you the real picture than a logo.
Frequently Asked Questions
The questions security and procurement teams ask us most.
Where is my data hosted?
The application and database run in Germany, in ISO 27001 certified data centers. Files and backups stay in EU regions. A small set of operational services (authentication, billing, email delivery) processes minimal data under the EU-US Data Privacy Framework and Standard Contractual Clauses. The residency table above shows the full picture.
What data does OTNOS actually need from us?
None to start. Advisory monitoring works without uploading any asset inventory: you select the vendors and products you care about. If you choose to upload an inventory or SBOMs for automatic matching, that data stays in your isolated tenant, remains under your control, and can be deleted at any time.
Do you sign Data Processing Agreements?
Yes. Our DPA is based on the EU Commission's standard contractual clauses for processors (Implementing Decision 2021/915), with a named, current sub-processor list. Request it at [email protected].
How does OTNOS approach ISO 27001?
OTNOS is developed and operated against ISO/IEC 27001:2022. Our information security management system is implemented and operating: security policy, risk assessment, a Statement of Applicability covering all 93 Annex A controls, and automated evidence collection on every deployment. Formal certification is on our roadmap, and our documentation is available for customer review today.
Who is responsible for what?
Security of the service is a partnership. OTNOS is responsible for platform security: hosting, encryption, tenant isolation, backups, advisory quality and incident response. You are responsible for what happens inside your tenant: user accounts and roles, password and API key hygiene, the accuracy of anything you upload, and acting on the advisories we deliver. A detailed shared-responsibility matrix is part of our security overview, available on request.
How do I report a security vulnerability?
Email [email protected] with the details. We acknowledge reports within two business days and keep you informed until resolution. Please report responsibly: do not run penetration tests, automated vulnerability scanners, load or denial-of-service attempts, or other intrusive testing against the live OTNOS platform without our prior written permission, and never access or alter other customers' data. This protects service availability for our customers; it is not a limitation on running OTNOS in production.
What happens if OTNOS has an incident?
Live service status and incident history are public at status.otnos.com. If an incident affects your data, we notify you directly. Our documented breach-assessment process evaluates any personal-data impact within 72 hours, in line with GDPR Article 33.
Reporting a vulnerability in OTNOS
Found a security issue in the platform, its API or the MCP server? Report it to [email protected]. Our Vulnerability Management Policy describes what to include, how a report is handled (ISO/IEC 30111 and 29147), and the rules for good-faith research.
Read the Vulnerability Management Policy
Due-Diligence Questions?
We are glad to walk your security and legal teams through any of the above — DPA, sub-processor list, security details, or a questionnaire.
Contact Our TeamRead the Privacy Notice