For banks, insurers & financial services providers

Control you can evidence — device by device.

Regulators and internal audit do not ask whether you have your endpoints under control, but what you use to prove it. octoja records access, change, approval and patch level as a continuous body of evidence.

  • Every privileged access is documented — including the justification
  • Permissions end where the task ends
  • Point-in-time reports instead of reconstructed answers
26

permissions individually assignable

17

device actions separately permissioned

22

security checks

100 %

of administrative interventions logged

Starting position

Sound familiar?

As long as nobody asks, it goes unnoticed. The question comes anyway — usually with a deadline.

Permissions have grown organically — nobody can explain them any more.

Who accessed a workstation remotely, and when, cannot be evidenced cleanly.

Encryption is mandatory, yet the evidence is still missing.

External service providers work alongside you, but outside your logs.

Every audit question turns into a special analysis.

Scenario

Internal audit is reviewing privileged access. The question: which individuals accessed workstations in payment processing last quarter, under what permission — and was the affected person informed?

The access overview shows, per device, which groups have access and which rule grants it. The device log lists every session with person, time and action. Where consent was overridden, the recorded justification sits alongside it — without a dedicated permission it would not have been possible at all.

The patch compliance report evidences the position as at the reporting date, and the audit log evidences the changes to policies and groups. No collecting things together.

In use

Evidence as a design principle

Not logging bolted on after the fact, but a model that cannot be circumvented.

Logging with no back door

Entries are created as a side effect of processing, with user and time set by the framework — not by application code on a case-by-case basis.

Who sees what — and why

Access in two stages: first the tenant, then the device, refined by 17 action permissions. The justification chain can be traced at any time.

Remote access with consent

Enforceable centrally. Overriding it requires a dedicated permission and a logged justification. The screen locks automatically when the session ends.

Strong authentication

Two-factor authentication via TOTP, enforceable in the SSO flow as well. OpenID Connect with PKCE, passwords hashed with BCrypt, secrets never readable via the API.

Integrity monitoring

Baselines for directory permissions, files and the registry report deviations. Open SMB shares are surfaced along with their permissions.

Approvals with a decision-maker

Patch cycles carry the approval type, decision-maker, timestamp and a note — manual, automatic, promoted or emergency.

And that is not all

  • A dedicated instance instead of a shared tenant database
  • User audit and SLA report as PDF
  • Signed webhooks with HMAC
  • Checks for default administrator accounts
  • Certificate expiry with advance warning
  • Account audit across Windows, Linux and macOS

The permission and evidence model is hard to convey in writing. Against your structure, it is not.

Get trial access
Alerting & connectivity

The alert lands where your team already works.

An alert is only worth something once it reaches the right person at the right time — and closes itself again when the problem has gone.

Ticketing systems & PSA

Alerts raise a ticket where your team already works — and close it again on all-clear. Customer records can be imported.

  • DocBee
  • TANSS
  • TOPdesk
  • c-entron Service-Board
  • HaloPSA
  • Autotask
  • Jira Service Management
  • Freshservice
  • Inserve
  • Odoo Helpdesk
  • Codemeta

Alerting

Separate service hours per channel. Into the ticketing system during the day, by phone call to the on-call engineer at night — alerts outside those hours are held back, not discarded.

  • Microsoft Teams
  • E-Mail
  • Signierte Webhooks
  • SMS
  • Sprachanruf
  • WhatsApp
  • App-Push
  • Internes Ticket

Documentation & ITAM

The device estate is mirrored into your existing documentation rather than creating a second register.

  • Hudu
  • IT Glue
  • woasi
  • Jira Assets

Antivirus, EDR & vulnerabilities

Protection status and vulnerabilities come together in the same view as the rest of the estate — regardless of whose security software the customer runs.

  • Microsoft Defender
  • Bitdefender GravityZone
  • SentinelOne
  • CrowdStrike Falcon
  • Sophos
  • ESET
  • G DATA
  • Securepoint Antivirus Pro
  • ThreatDown (Malwarebytes)
  • Lywand Schwachstellenaudit

Backup — monitored across vendors

Firewalls & appliances

Hardware, storage and network without an agent

Server workloads

Evidence

Requirements and matching evidence

octoja holds no certification and does not replace an audit. The platform supplies the technical evidence these requirements rely on.

DORA

Management of ICT and third-party risk

Separate access profiles for external service providers, a log of every intervention, availability and incident reports.

BAIT / VAIT

Authorisation management and traceability

Two-stage access model with a justification chain, 26 logged object types, user audit report.

NIS2

Vulnerability handling and patch process

Documented patch cycles with approval, exclusion lists and success rates per ring.

GDPR Art. 32

Evidence of technical measures

Encryption status per drive, account audit, password policy checks, access logs.

Put your audit question to us

In the meeting we will show you which report and which log answers it — using real data from a trial instance.