Security & trust
Designed so we never hold your keys.
Principles
Keys stay with you
Agent private keys are generated in your environment and never leave it. OATHERA never receives them.
No route into your systems
The OATHERA service is never given network access into your environment. Only approval requests and token requests cross the line.
Your data stays put
OATHERA verifies and decides; your data flows from the agent to your systems, not through us.
Fail closed
Anything that cannot be verified is refused.
Short lived by default
Tokens expire in minutes; revocation takes effect within one token lifetime.
Open, reviewed cryptography
Ed25519, RFC 9421 HTTP Message Signatures, OIDC and SPIFFE; no proprietary crypto.
Verifiable records
Approvals and decisions are signed and chained so tampering is detectable.
Compliance
We will add SOC 2, ISO 27001 or other attestations here once achieved. In the meantime, review our Privacy Policy, Data Processing Agreement and Sub-processors, and request a security questionnaire at security@oathera.ai.