Security
Data handling and privacy
How OSTaaS isolates tenants, redacts evidence, and records sensitive actions.
OSTaaS is built so that proof can be shared without exposing sensitive information.
Tenant isolation
Every piece of data belongs to a workspace (tenant). Requests are scoped to the workspace you are signed into, so one tenant can never read another tenant's projects, sessions, or evidence.
Evidence redaction
Captured evidence is redacted before it is stored. Sensitive regions are masked, and each item carries a redaction status of pending, redacted, or approved. Only redacted or approved evidence appears in shared and public views. See Evidence for the review flow.
Audit logging
Sensitive actions — enabling an integration, changing workspace settings, opting into a preview feature — are written to an audit log with the actor and timestamp. This gives Owners and Admins an accountable history of change.
Authentication
Sign-in is delegated to established identity providers. OSTaaS does not store passwords for social sign-in, and sessions are managed with secure, HTTP-only cookies. Failed sign-ins never modify your account and always return a reference ID for support.
Data you control
You decide which integrations are connected and which preview features are on. Disabling an integration stops new data flowing to it; historical records are retained for your audit trail.
Last updated 2026-09-02