Oten Access

OTEN ACCESS PRODUCTS

Start with the access boundary you need to change.

Use Oten Endpoint when device evidence and source-side authority are missing, Oten Gateway when resources need their own enforcement boundary, and the Access Control Plane to connect both sides through versioned policy and confirmed outcomes.

Source-side agent

Oten Endpoint

Device identity, posture, private connectivity, and endpoint-side enforcement in one micro-modular agent.

  • Device identity, enrollment, and hardware-backed keys where the platform supports them.
  • Continuous posture evidence that stays qualified, fresh, and attributable.
  • Private connectivity and endpoint-side enforcement in one micro-modular agent.
Explore Oten Endpoint
Resource-side enforcement

Oten Gateway

Resource-side enforcement for private applications, infrastructure, and privileged access.

  • Identity- and device-aware access to private applications and APIs at Layer 7.
  • Route, session, and upstream-identity policy applied next to the protected resource.
  • Group-scoped data-plane topology with explicit failover boundaries.
Explore Oten Gateway
Decision and desired state

Access Control Plane

Policy decision, signed desired state, trust context, and audit correlation.

  • Policy decisions from identity, device, resource, and condition context.
  • Signed, versioned desired state distributed to Endpoint and Gateway.
  • Trust context and audit correlation across the whole access path.
Explore Access Control Plane

How they work together

A request is qualified at the Endpoint, evaluated against signed policy in the Control Plane, and enforced at the Gateway. The decision closes only after every required enforcement point confirms the versioned action.
See the full architecture →

Choose the component boundary that solves the first problem.

Then define the deployment, platform, protocol, failure, and evidence scope required to connect that component to the full access system.