Digital sovereignty starts at the endpoint.
Public sector IT has to be able to demonstrate what runs on every device, who has accessed it and when it was last patched. With octoja this evidence is generated during normal operation — in an instance that belongs to you alone.
- Audit requests become a query rather than a project
- One agent for the town hall, the depot, the school and the server room
- Your own instance, your own domain, an open interface
object types in the audit log
device actions individually permissioned
interface languages
databases shared with anyone else
Sound familiar?
None of this is down to a lack of willingness — it is down to tools that do not work together.
The audit office asks about patch levels — and a week of manual work begins.
Town hall, depot, nursery, fire service: different technology everywhere, no shared picture anywhere.
The IT post has been vacant for a year; the work has not gone away.
An update rolls out on the day of the public advice surgery.
Remote access to workstations is a staff-relations matter — and barely documented.
The audit office wants to know whether the workstations in the citizens' office are up to date with patching and who has accessed them administratively over the past six months.
Instead of collecting screenshots from three different tools, you open the patch compliance report for the site and export it as a PDF. The device log shows every remote support session with a timestamp, the person and the action — including the justification, should user consent ever have been overridden.
The answer is ready before lunch. No special analysis required, because the data is being generated continuously anyway.
Evidence that accumulates along the way
What auditors want to see is usually already there. It just has to be retrievable.
An audit log with no way around it
Who changed which setting, which user, which rule and when — with a before-and-after comparison. Visible to administrators only.
Evidence of encryption per drive
BitLocker status with method, encryption level and key protector is held in the inventory — and can be monitored on top of that.
Maintenance windows that show consideration
Approvals with decision-maker and timestamp, separate windows per ring, restarts deferrable more than once by the user.
Deviations from the baseline
Permission drift, file and registry changes as well as open SMB shares with their share and NTFS permissions are reported.
Sign-in via your directory service
OpenID Connect with multiple providers and PKCE, plus two-factor authentication via TOTP — enforceable in the SSO flow as well.
Small teams stay able to act
Automations take care of the recurring work: apply security settings, remove bloatware, restart servers with verification. 30 templates are included.
And that is not all
- Agentless monitoring via SNMP v3
- Site structure with separate reports per facility
- Automatic tagging via rules
- Inventory history with change comparison
- Scheduled report delivery
- An open REST API against vendor lock-in
Which of these matter to you depends on your structure. That is exactly what we clarify in conversation.
Get trial accessThe alert lands where your team already works.
An alert is only worth something once it reaches the right person at the right time — and closes itself again when the problem has gone.
Ticketing systems & PSA
Alerts raise a ticket where your team already works — and close it again on all-clear. Customer records can be imported.
- DocBee
- TANSS
- TOPdesk
- c-entron Service-Board
- HaloPSA
- Autotask
- Jira Service Management
- Freshservice
- Inserve
- Odoo Helpdesk
- Codemeta
Alerting
Separate service hours per channel. Into the ticketing system during the day, by phone call to the on-call engineer at night — alerts outside those hours are held back, not discarded.
- Microsoft Teams
- Signierte Webhooks
- SMS
- Sprachanruf
- App-Push
- Internes Ticket
Documentation & ITAM
The device estate is mirrored into your existing documentation rather than creating a second register.
- Hudu
- IT Glue
- woasi
- Jira Assets
Antivirus, EDR & vulnerabilities
Protection status and vulnerabilities come together in the same view as the rest of the estate — regardless of whose security software the customer runs.
- Microsoft Defender
- Bitdefender GravityZone
- SentinelOne
- CrowdStrike Falcon
- Sophos
- ESET
- G DATA
- Securepoint Antivirus Pro
- ThreatDown (Malwarebytes)
- Lywand Schwachstellenaudit
Backup — monitored across vendors
Firewalls & appliances
Hardware, storage and network without an agent
Server workloads
What you are dealing with — and what octoja contributes
octoja is not a certification and does not replace an audit. The platform does, however, produce exactly the technical evidence these frameworks call for.
NIS2 / BSI IT-Grundschutz
Demonstrable patch and vulnerability management
Patch cycles with documented approval, success rate per ring and a compliance report as PDF.
GDPR Art. 32
Evidence of technical and organisational measures
Encryption status per device, role and access model with a justification chain, access logs.
Internal audit
Traceability of administrative interventions
Device log covering every remote support action with person, time and justification where consent was overridden.
Procurement & tendering
Avoiding vendor lock-in
A permanently open, documented REST API and a dedicated instance rather than a shared tenant database.
Would something else suit you better?
We will show it against your structure
A single meeting in which we work through your sites, your permission structure and a real audit question from your working day.