OTRISK
Product · Security & architecture

Built to pass your own procurement.

You assess suppliers for a living, so this page is written for your security reviewer: how OTRISK is built, who can touch what, where data lives, and the paper that proves it. If a question isn't answered here, the security documentation pack follows the same day you ask.

The architecture, plainly

Isolation
A dedicated application instance and database per client
Your own application instance and your own database. No shared multi-tenant environment, no commingled data, no noisy neighbours. Clean separation from the start, not bolted on.
Data residency
EU hosting
Your environment runs on EU infrastructure and your data stays in the EU. Where a regulator or your own policy asks for specifics, the documentation pack names region and provider.
Access
Roles, MFA, least privilege
Role-based access for operators, assessors, reviewers and auditors, behind multi-factor authentication. Third parties see their assignments, not your estate.
Evidence handling
Policy-checked downloads
Evidence is served only through access-policy checks: no public links, no guessable URLs. Who may see a document is decided at request time, every time.
Traceability
A log that doesn't forget
Every status change carries actor, timestamp and comment, permanently. The audit trail that serves your compliance also covers ours: what happened in your environment is answerable.
Content licensing
Standards, licensed properly
Standard content in the platform is used under signed licensing arrangements, and clients keep their own licensed copies of the standards. Independence, on the record.

What we deliberately don't do

No sensors, no agents. Nothing of ours touches your OT network. Assessments start from documents, drawings and interviews; monitoring exports can join later as evidence.
No LLMs on your plant data. The diagram parser is deterministic: it prefills only what it can read with certainty and flags the rest for a human. It never guesses.
No shared environments. There is no multi-tenant tier to upgrade away from. Every client gets a dedicated application instance and database, from day one.
No silent scope creep. We publish what the platform does and doesn't do yet; the clause-by-clause gap analysis is part of the documentation pack.
No forced uploads. For the most cautious environments, evidence can be a reference to a document in your own managed store: SharePoint, Tresorit, your DMS. OTRISK holds the pointer, the owner and the verdict; the file itself never leaves your environment.
No lock-in on your evidence. Uploaded or referenced, evidence stays yours: reports generate on demand and audit data exports to XLSX or PDF.
The security documentation pack. Architecture notes, subprocessors, backup and retention, incident process, access model. The long tail your reviewer will ask about, in one pack. Request it in the first call, or mail info@otrisk.io; it arrives the same day. The security review of OTRISK should be a short meeting.

Questions your reviewer will ask

Can our auditor get access instead of exports?

Yes. Auditors get their own role with read access to what they audit, and every view is logged like everything else. Exports remain available when they prefer paper.

What do third parties see in our environment?

Their assignments: the requirements they answer and the evidence they submitted. Verdicts stay separate. Their lead approves internally, your lead gives the final word.

How do we get our data out?

Your assessments, evidence and logs are yours. Reports generate on demand and audit data exports to XLSX or PDF. Leaving is not held hostage.

Do you run your own compliance in OTRISK?

Yes. We assess our own security posture in our own product, the same loop we sell. Ask about it in the demo; you judge the product and our posture in one conversation.

Bring your security reviewer to the first call.

Thirty minutes, an OT security expert on our side, the documentation pack on the table. Procurement shouldn't take longer than the first assessment.