Third Party Index

Snapshot 27822

Document
Trust center
URL
https://otrs.com/trust-center/
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
452034 bytes
SHA-256 (raw)
7bea94bb38dbd9dab274ee0f0487ef3286ad16824bd4c7c5af57655ccb70a1a8
SHA-256 (normalized text)
fee65ab0dabd980d5eca5e32a01451c8feaa9239705f8745bf50f78de8fb9c6a

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Security, Privacy and Reliability
Trust is built through transparency.
Learn how OTRS protects customer data, develops secure software, manages vulnerabilities, and operates resilient services worldwide.
Security Announcements
Responsible Disclosure
Privacy Information
Contact Security Team
Security
CVE Numbering Authority
Responsible Disclosure
Security Advisories
Security.txt Published
Identity & Access
Mandatory MFA
Central Identity Management
Zero Trust Architecture
Endpoint Security
Managed Linux Devices
Managed macOS Devices
Full Disk Encryption
Mobile Device Management
Resilience
Daily Backups
Recovery Testing
Multi Datacenter Strategy
Cyber Insurance
Security
Security by Design
Vulnerability Management
Security Testing
Zero Trust Architecture
Endpoint Security
Security by Design
Security is integrated throughout the complete software lifecycle.
Security requirements are considered during planning, development, testing, deployment, and maintenance activities.
Security controls include:
Secure Development Lifecycle
Automated Security Scanning
Code Reviews
Dependency Monitoring
Vulnerability Assessments
Security Testing
Vulnerability Management
OTRS maintains a structured vulnerability management program covering products, services, and supporting infrastructure.
As an accredited CVE Numbering Authority (CNA), OTRS actively contributes to the global vulnerability disclosure ecosystem.
Capabilities include:
Vulnerability Monitoring
CVE Assignment
Coordinated Disclosure
Security Advisories
Risk-Based Remediation
Security information is published through OTRS Security Announcements and CVE publications where applicable.
Security Testing
OTRS products are continuously evaluated through:
Internal Security Reviews
Coordinated Vulnerability Disclosure
Customer Security Assessments
Security Reviews by Public Sector Organizations
Penetration Testing Activities
Relevant findings are integrated into established remediation processes.
Zero Trust Architecture
OTRS follows a Zero Trust security model.
Access decisions are based on:
Identity
Device Compliance
Least Privilege
Continuous Verification
OTRS does not rely on a traditional trusted internal corporate network.
Endpoint Security
OTRS operates in a remote-first workplace environment.
Security measures include:
Managed Linux and macOS endpoints
Full disk encryption
Mobile Device Management
Secure baseline configurations
Device compliance monitoring
Mandatory MFA
OTRS does not utilize standard Windows-based employee workstations.
Privacy & Data Protection
Privacy by Design​
Global Privacy Compliance
Data Subject Rights
Data Protection Officer​
OTRS incorporates privacy and data protection principles throughout the design, development, and operation of its products and services.
Data protection considerations are integrated into business processes, software development activities, and operational procedures to ensure compliance with applicable privacy regulations and customer requirements.
OTRS is committed to complying with applicable privacy and data protection laws in the regions where its customers operate.
Depending on the service and deployment model, OTRS supports customer compliance obligations under regulations including:
European Union
General Data Protection Regulation (GDPR)
California
California Consumer Privacy Act (CCPA)
California Privacy Rights Act (CPRA)
Brazil
Lei Geral de Proteção de Dados (LGPD)
Singapore
Personal Data Protection Act (PDPA)
OTRS continuously evaluates evolving legal and regulatory requirements to maintain appropriate privacy controls and contractual safeguards.
Individuals whose personal data is processed by OTRS may exercise applicable privacy rights subject to legal and contractual limitations.
Requests regarding personal data may be submitted through the designated privacy contact channels.
OTRS has appointed a Data Protection Officer (DPO) responsible for overseeing privacy compliance and supporting data protection activities.
Contact Information
Data Protection Officer OTRS
[email protected]
External Data Protection Officer
[email protected]
For privacy-related inquiries, data subject requests, or data protection concerns, please contact our Data Protection Officer directly.
Data Processing Agreements
Technical and Organizational Measures (TOMs)
Sub processors
Data Access Controls
Encryption
OTRS provides Data Processing Agreements (DPAs) to support customer compliance obligations under applicable privacy regulations.
The DPA defines:
Processing activities
Responsibilities of the parties
Technical and organizational measures
International transfer safeguards
Subprocessor obligations
Resources
Data Processing Agreement
OTRS maintains documented technical and organizational measures designed to protect personal information and customer data.
Additional information may be provided under appropriate confidentiality obligations.
Resources
Technical and Organizational Measures (TOMs)
OTRS utilizes carefully selected sub processors to support the delivery and operation of its services.
All sub processors are subject to contractual, security, and privacy requirements appropriate to the services they provide.
Resources
Current Sub processor List
Access to customer information follows the principle of least privilege.
Customer data is only accessible to authorized personnel where required for:
Service Operations
Support Activities
Security Investigations
Legal Requirements
Security controls include:
TLS Encryption
Encryption at REST
Secure Credential Management
Infrastructure & Availability
Hosting Infrastructure
Depending on region and service offering, OTRS utilizes infrastructure provided by:
Europe
Hetzner (https://www.hetzner.com/unternehmen/zertifizierung/)
Oracle Cloud Infrastructure (https://www.oracle.com/de/corporate/cloud-compliance/)
North America
Oracle Cloud Infrastructure (https://www.oracle.com/de/corporate/cloud-compliance/)
OVHcloud (https://www.ovhcloud.com/en/personal-data-protection/legal-privacy-security/)
Asia-Pacific
OVHcloud (https://www.ovhcloud.com/en/personal-data-protection/legal-privacy-security/)
The respective datacenter operators maintain independent certifications and controls covering:
Physical Security
Environmental Controls
Operational Resilience
Infrastructure Protection
Regional Hosting
Available hosting regions include:
Europe
North America
Asia-Pacific
Availability depends on service offerings.
Backup & Recovery
Full backups are retained according to an exponential expiry schedule, keeping a total of 8 full backups at any given time, with progressively longer intervals between older backups. This schedule provides weekly full backups for the most recent four weeks, while the oldest full backup reaches back a minimum of six months. In addition, the six most recent incremental backups are retained, providing daily restore points for the past week.
Additional controls:
Continuous Monitoring
Automatic Failure Escalation
Regular Recovery Testing
Recovery procedures are regularly tested by the OTRS Operations Team.
Business Continuity
OTRS maintains business continuity processes supporting:
Operational Resilience
Disaster Recovery
Incident Management
Service Recovery
Compliance & Governance
Security Governance
Framework Alignment
Cyber Insurance
Security governance includes:
Chief Information Security Officer
Data Protection Officer
Executive Management Oversight
Security risks are reviewed regularly and incorporated into business decisions.
OTRS security processes are informed by:
NIS2
BSI IT-Grundschutz
ISO/IEC 27001 Controls
NIST Cybersecurity Framework
NIST SP 800-53
SANS Incident Response Guidance
RFC 9116
Important Note
OTRS currently does not maintain ISO 27001 or SOC 2 certification.
OTRS maintains cybersecurity insurance coverage as EasyVista company as part of its overall risk management strategy.
Responsible Disclosure
OTRS supports responsible vulnerability disclosure.
Security Contact:
[email protected]
Additional contact information and the PGP key is published through:
https://otrs.com/.well-known/security.txt
Frequently Asked Questions (FAQ)
Do you perform penetration tests?
Yes. OTRS products and services are continuously evaluated through internal reviews, coordinated vulnerability disclosure activities, customer-led assessments, and security reviews performed by cybersecurity-focused organizations.
How do you manage vulnerabilities?
OTRS maintains a formal vulnerability management process and acts as an accredited CVE Numbering Authority.
Why is SSH publicly accessible?
SSH supports secure administration and operational requirements. Access is protected through public-key authentication, least-privilege controls, monitoring and automated attack mitigation.
How do you protect backups?
Full backups are retained according to an exponential expiry schedule, keeping a total of 8 full backups at any given time, with progressively longer intervals between older backups. This schedule provides weekly full backups for the most recent four weeks, while the oldest full backup reaches back a minimum of six months. In addition, the six most recent incremental backups are retained, providing daily restore points for the past week.
Are employee devices encrypted?
Yes. All managed endpoints have full disk encryption.
Do employees use managed devices?
Yes. OTRS employees use centrally managed Linux and macOS devices.
Do you operate according to Zero Trust principles?
Yes. Access decisions are based on verified identities, device compliance and least privilege.
Do you maintain cyber insurance?
Yes. OTRS maintains cybersecurity insurance as part of its risk management strategy.
How can security researchers contact OTRS?
Via [email protected]. You will find the PGP key in the published security.txt information.