SECURITY & CONTROL

Make the trust boundary
explicit.

Who can see a document, where it lives, and how its history can be verified are part of the product—not an afterthought.

Access is scoped

Permissions are evaluated for each request. Search results and source links respect the same document boundaries as the viewer.

Data stays in its environment

The customer data plane contains documents, databases, object storage, keys, identities, audit data and operational telemetry.

Support starts with permission

Octopus has no standing access by default. Any support access is customer-approved, scoped, time-bounded, revocable and audited.

EVIDENCE YOU CAN TAKE WITH YOU

A record that can
be checked independently.

01

Document provenance

Signed manifests bind document content hashes, upload details and timestamps. Recipients can verify the record against a trusted signing key.

02

Attributable audit events

Signed audit attestations and a linked event history help make alterations detectable when verified against independently trusted keys.

03

Encrypted closing archives

Authorised exports bundle retained documents and scoped evidence, encrypted to recipient-owned keys for offline verification.

Security is a shared responsibility.

Octopus supplies software, versioned releases and documentation. The customer or contracted operator owns the accepted installation and its ongoing operation.

Software & updates
Octopus supplies versioned artifacts and fixes; the operator approves and installs releases.
Infrastructure & identity
The customer or dedicated operator manages cloud accounts, access, keys, storage and identity.
Backups & operations
The operator defines retention, tests recovery, routes alerts and owns incident response.
Support access
The customer approves any temporary support access and can revoke it.

A CLEARER WAY TO RUN DILIGENCE

Your next transaction.
Under your control.

Let’s discuss your deal process, access requirements and deployment environment.

Discuss your requirements