Security architecture

Security controls that match the product customers use today.

OZVO applies explicit identity, least privilege, local authority, and evidence-backed decisions across its current Early Access release. Future controls remain clearly labeled.

Available

Implemented today.

These controls are part of the current qualified OZVO architecture; they are not certification claims.

Explicit identity and MFA

Remote browser access uses OIDC, MFA, secure short-lived sessions, and assigned tenant/site scope.

Least-privilege authorization

Role, account state, tenant, site, appliance, route, and local authorization are evaluated at the relevant boundary.

Endpoint cryptographic identity

The Windows Agent uses an authenticated device identity with a non-exportable endpoint key and issued certificate.

Outbound-only remote access

OZVO Edge initiates the encrypted relay connection. Remote access requires no inbound customer port-forward or Internet-exposed SSH.

Allowlisted routes

The remote path exposes only approved dashboard routes; it is not an arbitrary TCP tunnel.

Audit and revocation

Remote access and authorization events are auditable, while session and account-state changes support expiry and revocation.

Local resilience

Local dashboard and security functions remain available when cloud connectivity is interrupted.

Evidence provenance

OZVO distinguishes observed evidence, source, freshness, and typed unavailability rather than guessing protected state.

Customer-controlled support

Support authorization is site-scoped, purpose-bound, time-limited, revocable, and creates no standing vendor access.

Pilot Available

Limited, qualified capability.

Pilot workflows stay bounded by the available evidence and explicit customer authority.

Recommendations

Qualified recommendations surface evidence and context for human review.

Customer-approved protection

Limited protective workflows require explicit customer authority and defined policy boundaries.

Planned

Not represented as available.

Planned capabilities must complete qualification before they become customer-facing functionality.

Broader autonomous execution

Additional action classes remain Planned until their safety, policy, audit, and rollback boundaries are qualified.

Gateway and firewall modes

Broader network-control deployment modes are product direction, not a claim of current universal compatibility.

Advanced fleet and cloud management

Wider fleet operations and cloud analysis remain Planned; the current Remote Portal is already available.

Planned

Security readiness, based on evidence.

Future Security Readiness reporting is intended to organize technical evidence, map relevant observations to NIST CSF 2.0 outcomes, and support preparation for ISO/IEC 27001 assessments and cyber-insurance questionnaires.

Observed technical evidence and customer-provided policies or records will remain distinct. OZVO does not certify compliance, replace an auditor, determine insurance eligibility, or guarantee coverage or premium reductions.

Review Planned Security Readiness
Responsible disclosure

Security contact

OZVO values responsible security research, but a dedicated monitored public security-disclosure channel is not yet qualified.

Do not send vulnerabilities, credentials, secrets, or customer evidence through an unapproved public form. A formal channel remains an owner action before general availability.