Source-side agentOten Endpoint
Device identity, posture, private connectivity, and endpoint-side enforcement in one micro-modular agent.
- Device identity, enrollment, and hardware-backed keys where the platform supports them.
- Continuous posture evidence that stays qualified, fresh, and attributable.
- Private connectivity and endpoint-side enforcement in one micro-modular agent.
Explore Oten Endpoint →Resource-side enforcementOten Gateway
Resource-side enforcement for private applications, infrastructure, and privileged access.
- Identity- and device-aware access to private applications and APIs at Layer 7.
- Route, session, and upstream-identity policy applied next to the protected resource.
- Group-scoped data-plane topology with explicit failover boundaries.
Explore Oten Gateway →Decision and desired stateAccess Control Plane
Policy decision, signed desired state, trust context, and audit correlation.
- Policy decisions from identity, device, resource, and condition context.
- Signed, versioned desired state distributed to Endpoint and Gateway.
- Trust context and audit correlation across the whole access path.
Explore Access Control Plane →