Security, Privacy and Reliability

Trust is built through transparency.

Learn how OTRS protects customer data, develops secure software, manages vulnerabilities, and operates resilient services worldwide.
OTRS Trust-Center
check-shield
Security

CVE Numbering Authority
Responsible Disclosure
Security Advisories
Security.txt Published

touch-id-approved
Identity & Access

Mandatory MFA
Central Identity Management
Zero Trust Architecture

phone-action-warning
Endpoint Security

Managed Linux Devices
Managed macOS Devices
Full Disk Encryption
Mobile Device Management

Resilience

Daily Backups
Recovery Testing
Multi Datacenter Strategy
Cyber Insurance

Security

Security by Design
Vulnerability Management
Security Testing
Zero Trust Architecture
Endpoint Security

Privacy & Data Protection

OTRS incorporates privacy and data protection principles throughout the design, development, and operation of its products and services.

Data protection considerations are integrated into business processes, software development activities, and operational procedures to ensure compliance with applicable privacy regulations and customer requirements.

OTRS is committed to complying with applicable privacy and data protection laws in the regions where its customers operate. 

Depending on the service and deployment model, OTRS supports customer compliance obligations under regulations including: 

European Union 

  • General Data Protection Regulation (GDPR)  

California 

  • California Consumer Privacy Act (CCPA)  
  • California Privacy Rights Act (CPRA)  

Brazil 

  • Lei Geral de Proteção de Dados (LGPD)  

Singapore 

  • Personal Data Protection Act (PDPA)  

 

OTRS continuously evaluates evolving legal and regulatory requirements to maintain appropriate privacy controls and contractual safeguards. 

Individuals whose personal data is processed by OTRS may exercise applicable privacy rights subject to legal and contractual limitations.

Requests regarding personal data may be submitted through the designated privacy contact channels.

OTRS has appointed a Data Protection Officer (DPO) responsible for overseeing privacy compliance and supporting data protection activities.

Contact Information

Data Protection Officer OTRS

privacy@otrs.com

External Data Protection Officer

aumiller@iitr.de

For privacy-related inquiries, data subject requests, or data protection concerns, please contact our Data Protection Officer directly.

OTRS provides Data Processing Agreements (DPAs) to support customer compliance obligations under applicable privacy regulations.

The DPA defines:

  • Processing activities
  • Responsibilities of the parties
  • Technical and organizational measures
  • International transfer safeguards
  • Subprocessor obligations

Resources

OTRS maintains documented technical and organizational measures designed to protect personal information and customer data.

Additional information may be provided under appropriate confidentiality obligations.

Resources

 

OTRS utilizes carefully selected sub processors to support the delivery and operation of its services.

All sub processors are subject to contractual, security, and privacy requirements appropriate to the services they provide.

Resources

Access to customer information follows the principle of least privilege.

Customer data is only accessible to authorized personnel where required for:

  • Service Operations
  • Support Activities
  • Security Investigations
  • Legal Requirements

Security controls include:

  • TLS Encryption
  • Encryption at REST
  • Secure Credential Management

Infrastructure & Availability

Hosting Infrastructure

Depending on region and service offering, OTRS utilizes infrastructure provided by:

Europe

North America

Asia-Pacific

The respective datacenter operators maintain independent certifications and controls covering:

  • Physical Security
  • Environmental Controls
  • Operational Resilience
  • Infrastructure Protection

Regional Hosting

Available hosting regions include:

  • Europe
  • North America
  • Asia-Pacific

Availability depends on service offerings.

Backup & Recovery

Full backups are retained according to an exponential expiry schedule, keeping a total of 8 full backups at any given time, with progressively longer intervals between older backups. This schedule provides weekly full backups for the most recent four weeks, while the oldest full backup reaches back a minimum of six months. In addition, the six most recent incremental backups are retained, providing daily restore points for the past week.

Additional controls:

  • Continuous Monitoring
  • Automatic Failure Escalation
  • Regular Recovery Testing

Recovery procedures are regularly tested by the OTRS Operations Team.

Business Continuity

OTRS maintains business continuity processes supporting:

  • Operational Resilience
  • Disaster Recovery
  • Incident Management
  • Service Recovery

Compliance & Governance

Security governance includes:

  • Chief Information Security Officer
  • Data Protection Officer
  • Executive Management Oversight

Security risks are reviewed regularly and incorporated into business decisions.

OTRS security processes are informed by:

  • NIS2
  • BSI IT-Grundschutz
  • ISO/IEC 27001 Controls
  • NIST Cybersecurity Framework
  • NIST SP 800-53
  • SANS Incident Response Guidance
  • RFC 9116

Important Note

OTRS currently does not maintain ISO 27001 or SOC 2 certification.

OTRS maintains cybersecurity insurance coverage as EasyVista company as part of its overall risk management strategy.

Responsible Disclosure

OTRS supports responsible vulnerability disclosure.

Security Contact:

security@otrs.com

Additional contact information and the PGP key is published through:

https://otrs.com/.well-known/security.txt

Frequently Asked Questions (FAQ)

Do you perform penetration tests?

Yes. OTRS products and services are continuously evaluated through internal reviews, coordinated vulnerability disclosure activities, customer-led assessments, and security reviews performed by cybersecurity-focused organizations.

OTRS maintains a formal vulnerability management process and acts as an accredited CVE Numbering Authority.

SSH supports secure administration and operational requirements. Access is protected through public-key authentication, least-privilege controls, monitoring and automated attack mitigation.

Full backups are retained according to an exponential expiry schedule, keeping a total of 8 full backups at any given time, with progressively longer intervals between older backups. This schedule provides weekly full backups for the most recent four weeks, while the oldest full backup reaches back a minimum of six months. In addition, the six most recent incremental backups are retained, providing daily restore points for the past week.

Yes. All managed endpoints have full disk encryption.

Yes. OTRS employees use centrally managed Linux and macOS devices.

Yes. Access decisions are based on verified identities, device compliance and least privilege.

Yes. OTRS maintains cybersecurity insurance as part of its risk management strategy.

Via security@otrs.com. You will find the PGP key in the published security.txt information.