Security & operations

Security you can verify.

octoja has far-reaching access to the devices you look after. That is why we set out openly how the platform is operated, which protective mechanisms are anchored in the product — and how to reach us if something strikes you as wrong.

Operations

Where the platform runs

Details of the infrastructure we operate ourselves.

Hetzner in Germany

The platform runs in a Kubernetes cluster at Hetzner. Their data centres are certified to ISO/IEC 27001 and attested under BSI C5. In normal operation, customer data does not leave Germany.

Recovery is rehearsed

Backups are not just created, they are restored regularly. A backup that has never been tested is not a backup.

Round-the-clock monitoring

The platform is monitored 24/7. You can check the current operational state yourself at any time.

Anchored in the product

Eight points you can hold us to

Properties of the software and fixed rules in our development process — several of them safeguarded by automated tests.

01

The agent connects outbound

The connection is always established from the endpoint to your instance, never the other way round, and runs exclusively over TLS. You do not have to open an inbound port or create a firewall rule for remote support.

02

Updates are verified and can be rolled back

Every downloaded file is verified via SHA256, and path traversal is blocked. The version switch is atomic and rolls back automatically if the start fails. Windows binaries are shipped signed.

03

No endpoint without a deliberate access decision

An architecture test fails the build as soon as an interface is neither explicitly protected nor explicitly opened. Forgetting is therefore technically impossible.

04

Login – state of the art

Single sign-on via Microsoft Entra ID, optionally with two-factor confirmation. Passwords are hashed with BCrypt, and the session cookie is exclusively HttpOnly and Secure. Revoked permissions take effect immediately — not at the next login.

05

Complete tenant isolation

Every customer receives their own environment with their own database — no shared data with other octoja customers. Within your environment, the permission model separates your own customers from one another, and does so in the database query itself rather than afterwards in memory.

06

Minimal data sent outward

What your instance reports back to us is limited to the instance identifier, the date and billing data. No hostnames, no IP addresses, no inventory data.

07

Four-eyes principle in code review

No change goes into the platform without a second person having reviewed and approved it. That applies to features just as much as to bug fixes.

08

Audits and penetration tests

The code is audited regularly. In addition, we test continuously in-house and commission external agencies to carry out penetration tests.

Responsible disclosure

Have you found a vulnerability?

Then we would like to hear about it before anyone else does. We acknowledge receipt within two working days.

Acknowledgement within 2 working daysReports are treated confidentially
Scope

What we want to hear about — and what we do not

So that your report reaches the right people quickly and you remain on safe legal ground.

In scope

The octoja platform and its web interface
The agent on managed endpoints (Tentacle and Launcher)
The public REST interface
This website and its subdomains

Please refrain from

Load testing, denial-of-service and automated bulk scanning
Social engineering directed at employees, partners or customers
Accessing other people's data, or altering or deleting third-party data
Vulnerabilities in other manufacturers' products that we merely integrate with

If you stay within this framework, act in good faith and give us reasonable time to remediate, we will not treat your report as grounds for legal action. Please publish details only after agreeing them with us.

Process

What happens after your report

01

Receipt acknowledged

You receive a response within two working days, naming a point of contact.

02

Assessment

We reproduce the finding, assess the impact and come back to you with an evaluation.

03

Remediation and feedback

We let you know as soon as a fix has shipped — and credit you as the finder if you wish.

Report

Report a vulnerability

For confidential or encrypted communication, please use the email address directly. Everything else can be entered here.

Please do not send credentials, third-party personal data or exploit code through this form. For that, please use security@octoja.de.