Snapshot 27822
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Security, Privacy and Reliability Trust is built through transparency. Learn how OTRS protects customer data, develops secure software, manages vulnerabilities, and operates resilient services worldwide. Security Announcements Responsible Disclosure Privacy Information Contact Security Team Security CVE Numbering Authority Responsible Disclosure Security Advisories Security.txt Published Identity & Access Mandatory MFA Central Identity Management Zero Trust Architecture Endpoint Security Managed Linux Devices Managed macOS Devices Full Disk Encryption Mobile Device Management Resilience Daily Backups Recovery Testing Multi Datacenter Strategy Cyber Insurance Security Security by Design Vulnerability Management Security Testing Zero Trust Architecture Endpoint Security Security by Design Security is integrated throughout the complete software lifecycle. Security requirements are considered during planning, development, testing, deployment, and maintenance activities. Security controls include: Secure Development Lifecycle Automated Security Scanning Code Reviews Dependency Monitoring Vulnerability Assessments Security Testing Vulnerability Management OTRS maintains a structured vulnerability management program covering products, services, and supporting infrastructure. As an accredited CVE Numbering Authority (CNA), OTRS actively contributes to the global vulnerability disclosure ecosystem. Capabilities include: Vulnerability Monitoring CVE Assignment Coordinated Disclosure Security Advisories Risk-Based Remediation Security information is published through OTRS Security Announcements and CVE publications where applicable. Security Testing OTRS products are continuously evaluated through: Internal Security Reviews Coordinated Vulnerability Disclosure Customer Security Assessments Security Reviews by Public Sector Organizations Penetration Testing Activities Relevant findings are integrated into established remediation processes. Zero Trust Architecture OTRS follows a Zero Trust security model. Access decisions are based on: Identity Device Compliance Least Privilege Continuous Verification OTRS does not rely on a traditional trusted internal corporate network. Endpoint Security OTRS operates in a remote-first workplace environment. Security measures include: Managed Linux and macOS endpoints Full disk encryption Mobile Device Management Secure baseline configurations Device compliance monitoring Mandatory MFA OTRS does not utilize standard Windows-based employee workstations. Privacy & Data Protection Privacy by Design Global Privacy Compliance Data Subject Rights Data Protection Officer OTRS incorporates privacy and data protection principles throughout the design, development, and operation of its products and services. Data protection considerations are integrated into business processes, software development activities, and operational procedures to ensure compliance with applicable privacy regulations and customer requirements. OTRS is committed to complying with applicable privacy and data protection laws in the regions where its customers operate. Depending on the service and deployment model, OTRS supports customer compliance obligations under regulations including: European Union General Data Protection Regulation (GDPR) California California Consumer Privacy Act (CCPA) California Privacy Rights Act (CPRA) Brazil Lei Geral de Proteção de Dados (LGPD) Singapore Personal Data Protection Act (PDPA) OTRS continuously evaluates evolving legal and regulatory requirements to maintain appropriate privacy controls and contractual safeguards. Individuals whose personal data is processed by OTRS may exercise applicable privacy rights subject to legal and contractual limitations. Requests regarding personal data may be submitted through the designated privacy contact channels. OTRS has appointed a Data Protection Officer (DPO) responsible for overseeing privacy compliance and supporting data protection activities. Contact Information Data Protection Officer OTRS [email protected] External Data Protection Officer [email protected] For privacy-related inquiries, data subject requests, or data protection concerns, please contact our Data Protection Officer directly. Data Processing Agreements Technical and Organizational Measures (TOMs) Sub processors Data Access Controls Encryption OTRS provides Data Processing Agreements (DPAs) to support customer compliance obligations under applicable privacy regulations. The DPA defines: Processing activities Responsibilities of the parties Technical and organizational measures International transfer safeguards Subprocessor obligations Resources Data Processing Agreement OTRS maintains documented technical and organizational measures designed to protect personal information and customer data. Additional information may be provided under appropriate confidentiality obligations. Resources Technical and Organizational Measures (TOMs) OTRS utilizes carefully selected sub processors to support the delivery and operation of its services. All sub processors are subject to contractual, security, and privacy requirements appropriate to the services they provide. Resources Current Sub processor List Access to customer information follows the principle of least privilege. Customer data is only accessible to authorized personnel where required for: Service Operations Support Activities Security Investigations Legal Requirements Security controls include: TLS Encryption Encryption at REST Secure Credential Management Infrastructure & Availability Hosting Infrastructure Depending on region and service offering, OTRS utilizes infrastructure provided by: Europe Hetzner (https://www.hetzner.com/unternehmen/zertifizierung/) Oracle Cloud Infrastructure (https://www.oracle.com/de/corporate/cloud-compliance/) North America Oracle Cloud Infrastructure (https://www.oracle.com/de/corporate/cloud-compliance/) OVHcloud (https://www.ovhcloud.com/en/personal-data-protection/legal-privacy-security/) Asia-Pacific OVHcloud (https://www.ovhcloud.com/en/personal-data-protection/legal-privacy-security/) The respective datacenter operators maintain independent certifications and controls covering: Physical Security Environmental Controls Operational Resilience Infrastructure Protection Regional Hosting Available hosting regions include: Europe North America Asia-Pacific Availability depends on service offerings. Backup & Recovery Full backups are retained according to an exponential expiry schedule, keeping a total of 8 full backups at any given time, with progressively longer intervals between older backups. This schedule provides weekly full backups for the most recent four weeks, while the oldest full backup reaches back a minimum of six months. In addition, the six most recent incremental backups are retained, providing daily restore points for the past week. Additional controls: Continuous Monitoring Automatic Failure Escalation Regular Recovery Testing Recovery procedures are regularly tested by the OTRS Operations Team. Business Continuity OTRS maintains business continuity processes supporting: Operational Resilience Disaster Recovery Incident Management Service Recovery Compliance & Governance Security Governance Framework Alignment Cyber Insurance Security governance includes: Chief Information Security Officer Data Protection Officer Executive Management Oversight Security risks are reviewed regularly and incorporated into business decisions. OTRS security processes are informed by: NIS2 BSI IT-Grundschutz ISO/IEC 27001 Controls NIST Cybersecurity Framework NIST SP 800-53 SANS Incident Response Guidance RFC 9116 Important Note OTRS currently does not maintain ISO 27001 or SOC 2 certification. OTRS maintains cybersecurity insurance coverage as EasyVista company as part of its overall risk management strategy. Responsible Disclosure OTRS supports responsible vulnerability disclosure. Security Contact: [email protected] Additional contact information and the PGP key is published through: https://otrs.com/.well-known/security.txt Frequently Asked Questions (FAQ) Do you perform penetration tests? Yes. OTRS products and services are continuously evaluated through internal reviews, coordinated vulnerability disclosure activities, customer-led assessments, and security reviews performed by cybersecurity-focused organizations. How do you manage vulnerabilities? OTRS maintains a formal vulnerability management process and acts as an accredited CVE Numbering Authority. Why is SSH publicly accessible? SSH supports secure administration and operational requirements. Access is protected through public-key authentication, least-privilege controls, monitoring and automated attack mitigation. How do you protect backups? Full backups are retained according to an exponential expiry schedule, keeping a total of 8 full backups at any given time, with progressively longer intervals between older backups. This schedule provides weekly full backups for the most recent four weeks, while the oldest full backup reaches back a minimum of six months. In addition, the six most recent incremental backups are retained, providing daily restore points for the past week. Are employee devices encrypted? Yes. All managed endpoints have full disk encryption. Do employees use managed devices? Yes. OTRS employees use centrally managed Linux and macOS devices. Do you operate according to Zero Trust principles? Yes. Access decisions are based on verified identities, device compliance and least privilege. Do you maintain cyber insurance? Yes. OTRS maintains cybersecurity insurance as part of its risk management strategy. How can security researchers contact OTRS? Via [email protected]. You will find the PGP key in the published security.txt information.