Explicit identity and MFA
Remote browser access uses OIDC, MFA, secure short-lived sessions, and assigned tenant/site scope.
OZVO applies explicit identity, least privilege, local authority, and evidence-backed decisions across its current Early Access release. Future controls remain clearly labeled.
These controls are part of the current qualified OZVO architecture; they are not certification claims.
Remote browser access uses OIDC, MFA, secure short-lived sessions, and assigned tenant/site scope.
Role, account state, tenant, site, appliance, route, and local authorization are evaluated at the relevant boundary.
The Windows Agent uses an authenticated device identity with a non-exportable endpoint key and issued certificate.
OZVO Edge initiates the encrypted relay connection. Remote access requires no inbound customer port-forward or Internet-exposed SSH.
The remote path exposes only approved dashboard routes; it is not an arbitrary TCP tunnel.
Remote access and authorization events are auditable, while session and account-state changes support expiry and revocation.
Local dashboard and security functions remain available when cloud connectivity is interrupted.
OZVO distinguishes observed evidence, source, freshness, and typed unavailability rather than guessing protected state.
Support authorization is site-scoped, purpose-bound, time-limited, revocable, and creates no standing vendor access.
See identity, encryption, privacy, data-residency, remote-access, and support-control boundaries.
Pilot workflows stay bounded by the available evidence and explicit customer authority.
Qualified recommendations surface evidence and context for human review.
Limited protective workflows require explicit customer authority and defined policy boundaries.
Planned capabilities must complete qualification before they become customer-facing functionality.
Additional action classes remain Planned until their safety, policy, audit, and rollback boundaries are qualified.
Broader network-control deployment modes are product direction, not a claim of current universal compatibility.
Wider fleet operations and cloud analysis remain Planned; the current Remote Portal is already available.
Future Security Readiness reporting is intended to organize technical evidence, map relevant observations to NIST CSF 2.0 outcomes, and support preparation for ISO/IEC 27001 assessments and cyber-insurance questionnaires.
Observed technical evidence and customer-provided policies or records will remain distinct. OZVO does not certify compliance, replace an auditor, determine insurance eligibility, or guarantee coverage or premium reductions.
Review Planned Security ReadinessOZVO values responsible security research, but a dedicated monitored public security-disclosure channel is not yet qualified.
Do not send vulnerabilities, credentials, secrets, or customer evidence through an unapproved public form. A formal channel remains an owner action before general availability.