For local authorities, public bodies & municipal enterprises

Digital sovereignty starts at the endpoint.

Public sector IT has to be able to demonstrate what runs on every device, who has accessed it and when it was last patched. With octoja this evidence is generated during normal operation — in an instance that belongs to you alone.

  • Audit requests become a query rather than a project
  • One agent for the town hall, the depot, the school and the server room
  • Your own instance, your own domain, an open interface
26

object types in the audit log

17

device actions individually permissioned

4

interface languages

0

databases shared with anyone else

Starting position

Sound familiar?

None of this is down to a lack of willingness — it is down to tools that do not work together.

The audit office asks about patch levels — and a week of manual work begins.

Town hall, depot, nursery, fire service: different technology everywhere, no shared picture anywhere.

The IT post has been vacant for a year; the work has not gone away.

An update rolls out on the day of the public advice surgery.

Remote access to workstations is a staff-relations matter — and barely documented.

Scenario

The audit office wants to know whether the workstations in the citizens' office are up to date with patching and who has accessed them administratively over the past six months.

Instead of collecting screenshots from three different tools, you open the patch compliance report for the site and export it as a PDF. The device log shows every remote support session with a timestamp, the person and the action — including the justification, should user consent ever have been overridden.

The answer is ready before lunch. No special analysis required, because the data is being generated continuously anyway.

In use

Evidence that accumulates along the way

What auditors want to see is usually already there. It just has to be retrievable.

An audit log with no way around it

Who changed which setting, which user, which rule and when — with a before-and-after comparison. Visible to administrators only.

Evidence of encryption per drive

BitLocker status with method, encryption level and key protector is held in the inventory — and can be monitored on top of that.

Maintenance windows that show consideration

Approvals with decision-maker and timestamp, separate windows per ring, restarts deferrable more than once by the user.

Deviations from the baseline

Permission drift, file and registry changes as well as open SMB shares with their share and NTFS permissions are reported.

Sign-in via your directory service

OpenID Connect with multiple providers and PKCE, plus two-factor authentication via TOTP — enforceable in the SSO flow as well.

Small teams stay able to act

Automations take care of the recurring work: apply security settings, remove bloatware, restart servers with verification. 30 templates are included.

And that is not all

  • Agentless monitoring via SNMP v3
  • Site structure with separate reports per facility
  • Automatic tagging via rules
  • Inventory history with change comparison
  • Scheduled report delivery
  • An open REST API against vendor lock-in

Which of these matter to you depends on your structure. That is exactly what we clarify in conversation.

Get trial access
Alerting & connectivity

The alert lands where your team already works.

An alert is only worth something once it reaches the right person at the right time — and closes itself again when the problem has gone.

Ticketing systems & PSA

Alerts raise a ticket where your team already works — and close it again on all-clear. Customer records can be imported.

  • DocBee
  • TANSS
  • TOPdesk
  • c-entron Service-Board
  • HaloPSA
  • Autotask
  • Jira Service Management
  • Freshservice
  • Inserve
  • Odoo Helpdesk
  • Codemeta

Alerting

Separate service hours per channel. Into the ticketing system during the day, by phone call to the on-call engineer at night — alerts outside those hours are held back, not discarded.

  • Microsoft Teams
  • E-Mail
  • Signierte Webhooks
  • SMS
  • Sprachanruf
  • WhatsApp
  • App-Push
  • Internes Ticket

Documentation & ITAM

The device estate is mirrored into your existing documentation rather than creating a second register.

  • Hudu
  • IT Glue
  • woasi
  • Jira Assets

Antivirus, EDR & vulnerabilities

Protection status and vulnerabilities come together in the same view as the rest of the estate — regardless of whose security software the customer runs.

  • Microsoft Defender
  • Bitdefender GravityZone
  • SentinelOne
  • CrowdStrike Falcon
  • Sophos
  • ESET
  • G DATA
  • Securepoint Antivirus Pro
  • ThreatDown (Malwarebytes)
  • Lywand Schwachstellenaudit

Backup — monitored across vendors

Firewalls & appliances

Hardware, storage and network without an agent

Server workloads

Evidence

What you are dealing with — and what octoja contributes

octoja is not a certification and does not replace an audit. The platform does, however, produce exactly the technical evidence these frameworks call for.

NIS2 / BSI IT-Grundschutz

Demonstrable patch and vulnerability management

Patch cycles with documented approval, success rate per ring and a compliance report as PDF.

GDPR Art. 32

Evidence of technical and organisational measures

Encryption status per device, role and access model with a justification chain, access logs.

Internal audit

Traceability of administrative interventions

Device log covering every remote support action with person, time and justification where consent was overridden.

Procurement & tendering

Avoiding vendor lock-in

A permanently open, documented REST API and a dedicated instance rather than a shared tenant database.

We will show it against your structure

A single meeting in which we work through your sites, your permission structure and a real audit question from your working day.