Oten Access

PRIVACY AND DATA HANDLING

Collect the minimum evidence required for access, security, and audit.

Oten Access separates identity, device, policy, enforcement, session, operational telemetry, and security evidence so each category can have a defined purpose, access boundary, retention rule, and deletion path.

System role: Privacy owner + Security owner + Customer data owner

Evaluation depends on: Requires an approved privacy notice, deployment data-flow inventory, retention schedule, regional scope, and subprocessor record.

The Access Control Plane makes policy decisions; Oten Endpoint and Oten Gateway enforce at opposite sides; Signal coordinates paths and Relay only forwards encrypted fallback traffic.

Data categories retain separate purposes and access boundaries.

Identity and device

Subject identifiers, device identity, enrollment, ownership, posture observations, evidence source, freshness, and reason codes used for policy.

Policy and enforcement

Policy identifiers and versions, decision inputs, reason codes, targeted enforcement points, acknowledgement, partial failure, and recovery state.

Connection and session

Resource, protocol, path mode, session identifiers, timing, and supported session evidence, without treating payload inspection as the default.

Operational telemetry

Service health, version, capacity, failure, rollout, and diagnostic data kept separate from user-content and security-investigation evidence.

Security evidence

Findings and bounded supporting evidence with purpose-based access, minimization, masking, retention, export, and review controls.

Evaluation requests

Business contact details and high-level evaluation context. Requests must exclude passwords, secrets, personal data, internal IPs, hostnames, and sensitive network diagrams.

Handling controls follow purpose and deployment responsibility.

  • Document purpose, lawful basis, controller and processor roles, and field-level collection scope.
  • Apply role-based access, least privilege, encryption, export control, access logging, and review.
  • Define residency, transfer, subprocessor, backup, restoration, and incident-notification boundaries.
  • Set retention and deletion by data category instead of using one global period.
  • Minimize or mask sensitive evidence and avoid storing file, clipboard, keystroke, or session content by default.
  • Provide employee, user, and administrator notices appropriate to the deployed monitoring and recording scope.

The technical-evaluation form is a bounded business-contact channel.

The form collects a name, work email, organization, role, evaluation topic, and high-level problem description only after consent. Delivery is enabled only when an approved destination, server-side credential, and privacy notice are configured together.

Make data handling part of the deployment design.

Map each data category to purpose, ownership, access, region, retention, deletion, and incident responsibility.