Oten Access

OTEN ACCESS PRODUCTS

One agent, one gateway, one control plane.

Oten Access is three products that share one trust context. Oten Endpoint qualifies the source, the Access Control Plane decides policy and records the outcome, and Oten Gateway enforces at the resource.

Source-side agent

Oten Endpoint

Device identity, posture, private connectivity, and endpoint-side enforcement in one micro-modular agent.

  • Device identity, enrollment, and hardware-backed keys where the platform supports them.
  • Continuous posture evidence that stays qualified, fresh, and attributable.
  • Private connectivity and endpoint-side enforcement in one micro-modular agent.
Explore Oten Endpoint
Resource-side enforcement

Oten Gateway

Resource-side enforcement for private applications, infrastructure, and privileged access.

  • Identity- and device-aware access to private applications and APIs at Layer 7.
  • Route, session, and upstream-identity policy applied next to the protected resource.
  • Group-scoped data-plane topology with explicit failover boundaries.
Explore Oten Gateway
Decision and desired state

Access Control Plane

Policy decision, signed desired state, trust context, and audit correlation.

  • Policy decisions from identity, device, resource, and condition context.
  • Signed, versioned desired state distributed to Endpoint and Gateway.
  • Trust context and audit correlation across the whole access path.
Explore Access Control Plane

How they work together

A request is qualified at the Endpoint, evaluated against signed policy in the Control Plane, and enforced at the Gateway. The decision closes only after every required enforcement point confirms the versioned action.
See the full architecture →

See how the three products enforce one decision.

Review the Continuous Trust Loop that connects Endpoint evidence, Control Plane policy, and Gateway enforcement into one auditable outcome.