Approval Queue
Review customer messages, publishing actions, purchase requests, billing steps and other external actions before they happen.
Ottili ONE is designed with security first. Approvals, permissions, audit trails, company isolation and a single-gateway architecture — all built in from the start, not added later.
Review customer messages, publishing actions, purchase requests, billing steps and other external actions before they happen.
Control who can access company data, modules, automations and settings.
Keep important actions, workflow results and AI decisions traceable.
Roll out modules and automation features carefully instead of breaking everything at once.
Monitor services, integrations, modules and system health from one platform view.
These are the technical security mechanisms built into the Ottili ONE platform.
Secure JWT access tokens with refresh token rotation. Revoked tokens trigger session invalidation. Refresh tokens are rotated on each use and reuse is detected and rejected.
All passwords are hashed with Argon2id — the current industry standard for password security. Passwords are never stored in plaintext.
Redis-backed rate limiting mitigates brute-force attacks. Throttling is enforced across instances.
Every record is scoped to your company workspace. Cross-company access requires explicit, audited operations.
External requests are routed through one authenticated API gateway. Internal services are not directly exposed to the public internet by design.
Every state-changing action is written to append-only, tamper-evident audit logs. Records are traceable and protected.
We are transparent about our certifications. Everything below comes from our canonical registry — what we hold, what is planned, and what we do not claim. We never present a certification we have not earned.
Ottili ONE is built for GDPR: data-subject rights, lawful bases, retention limits and sub-processor transparency are implemented and referenced throughout the privacy surface.
Last reviewed: 2026-07A SOC 2 Type II audit is on our compliance roadmap. No attestation has been completed yet; we do not claim SOC 2 certification.
ISO/IEC 27001 alignment is planned. Ottili is not yet certified; we do not claim ISO/IEC 27001 certification.
Not currently pursued; we do not claim this certification.
Get started today
Connect your tools, automate your daily work and keep control of every important action — all from one unified platform.
No credit card required. Start free and expand with modules.