Security, Privacy and Reliability
Learn how OTRS protects customer data, develops secure software, manages vulnerabilities, and operates resilient services worldwide.
CVE Numbering Authority
Responsible Disclosure
Security Advisories
Security.txt Published
Mandatory MFA
Central Identity Management
Zero Trust Architecture
Managed Linux Devices
Managed macOS Devices
Full Disk Encryption
Mobile Device Management
Daily Backups
Recovery Testing
Multi Datacenter Strategy
Cyber Insurance
Security
Security requirements are considered during planning, development, testing, deployment, and maintenance activities.
Security controls include:
- Secure Development Lifecycle
- Automated Security Scanning
- Code Reviews
- Dependency Monitoring
- Vulnerability Assessments
- Security Testing
As an accredited CVE Numbering Authority (CNA), OTRS actively contributes to the global vulnerability disclosure ecosystem.
Capabilities include:
- Vulnerability Monitoring
- CVE Assignment
- Coordinated Disclosure
- Security Advisories
- Risk-Based Remediation
Security information is published through OTRS Security Announcements and CVE publications where applicable.
- Internal Security Reviews
- Coordinated Vulnerability Disclosure
- Customer Security Assessments
- Security Reviews by Public Sector Organizations
- Penetration Testing Activities
Access decisions are based on:
- Identity
- Device Compliance
- Least Privilege
- Continuous Verification
Security measures include:
- Managed Linux and macOS endpoints
- Full disk encryption
- Mobile Device Management
- Secure baseline configurations
- Device compliance monitoring
- Mandatory MFA
Privacy & Data Protection
OTRS incorporates privacy and data protection principles throughout the design, development, and operation of its products and services.
Data protection considerations are integrated into business processes, software development activities, and operational procedures to ensure compliance with applicable privacy regulations and customer requirements.
OTRS is committed to complying with applicable privacy and data protection laws in the regions where its customers operate.
Depending on the service and deployment model, OTRS supports customer compliance obligations under regulations including:
European Union
- General Data Protection Regulation (GDPR)
California
- California Consumer Privacy Act (CCPA)
- California Privacy Rights Act (CPRA)
Brazil
- Lei Geral de Proteção de Dados (LGPD)
Singapore
- Personal Data Protection Act (PDPA)
OTRS continuously evaluates evolving legal and regulatory requirements to maintain appropriate privacy controls and contractual safeguards.
Individuals whose personal data is processed by OTRS may exercise applicable privacy rights subject to legal and contractual limitations.
Requests regarding personal data may be submitted through the designated privacy contact channels.
OTRS has appointed a Data Protection Officer (DPO) responsible for overseeing privacy compliance and supporting data protection activities.
Contact Information
Data Protection Officer OTRS
External Data Protection Officer
For privacy-related inquiries, data subject requests, or data protection concerns, please contact our Data Protection Officer directly.
- Data Processing Agreements
- Technical and Organizational Measures (TOMs)
- Sub processors
- Data Access Controls
- Encryption
OTRS provides Data Processing Agreements (DPAs) to support customer compliance obligations under applicable privacy regulations.
The DPA defines:
- Processing activities
- Responsibilities of the parties
- Technical and organizational measures
- International transfer safeguards
- Subprocessor obligations
Resources
OTRS maintains documented technical and organizational measures designed to protect personal information and customer data.
Additional information may be provided under appropriate confidentiality obligations.
Resources
OTRS utilizes carefully selected sub processors to support the delivery and operation of its services.
All sub processors are subject to contractual, security, and privacy requirements appropriate to the services they provide.
Resources
Access to customer information follows the principle of least privilege.
Customer data is only accessible to authorized personnel where required for:
- Service Operations
- Support Activities
- Security Investigations
- Legal Requirements
Security controls include:
- TLS Encryption
- Encryption at REST
- Secure Credential Management
Infrastructure & Availability
Hosting Infrastructure
Depending on region and service offering, OTRS utilizes infrastructure provided by:
Europe
- Hetzner (https://www.hetzner.com/unternehmen/zertifizierung/)
- Oracle Cloud Infrastructure (https://www.oracle.com/de/corporate/cloud-compliance/)
North America
- Oracle Cloud Infrastructure (https://www.oracle.com/de/corporate/cloud-compliance/)
- OVHcloud (https://www.ovhcloud.com/en/personal-data-protection/legal-privacy-security/)
Asia-Pacific
The respective datacenter operators maintain independent certifications and controls covering:
- Physical Security
- Environmental Controls
- Operational Resilience
- Infrastructure Protection
Regional Hosting
Available hosting regions include:
- Europe
- North America
- Asia-Pacific
Availability depends on service offerings.
Backup & Recovery
Full backups are retained according to an exponential expiry schedule, keeping a total of 8 full backups at any given time, with progressively longer intervals between older backups. This schedule provides weekly full backups for the most recent four weeks, while the oldest full backup reaches back a minimum of six months. In addition, the six most recent incremental backups are retained, providing daily restore points for the past week.
Additional controls:
- Continuous Monitoring
- Automatic Failure Escalation
- Regular Recovery Testing
Recovery procedures are regularly tested by the OTRS Operations Team.
Business Continuity
OTRS maintains business continuity processes supporting:
- Operational Resilience
- Disaster Recovery
- Incident Management
- Service Recovery
Compliance & Governance
Security governance includes:
- Chief Information Security Officer
- Data Protection Officer
- Executive Management Oversight
Security risks are reviewed regularly and incorporated into business decisions.
OTRS security processes are informed by:
- NIS2
- BSI IT-Grundschutz
- ISO/IEC 27001 Controls
- NIST Cybersecurity Framework
- NIST SP 800-53
- SANS Incident Response Guidance
- RFC 9116
Important Note
OTRS currently does not maintain ISO 27001 or SOC 2 certification.
OTRS maintains cybersecurity insurance coverage as EasyVista company as part of its overall risk management strategy.
Responsible Disclosure
OTRS supports responsible vulnerability disclosure.
Security Contact:
Additional contact information and the PGP key is published through:
Frequently Asked Questions (FAQ)
Do you perform penetration tests?
Yes. OTRS products and services are continuously evaluated through internal reviews, coordinated vulnerability disclosure activities, customer-led assessments, and security reviews performed by cybersecurity-focused organizations.
How do you manage vulnerabilities?
OTRS maintains a formal vulnerability management process and acts as an accredited CVE Numbering Authority.
Why is SSH publicly accessible?
SSH supports secure administration and operational requirements. Access is protected through public-key authentication, least-privilege controls, monitoring and automated attack mitigation.
How do you protect backups?
Full backups are retained according to an exponential expiry schedule, keeping a total of 8 full backups at any given time, with progressively longer intervals between older backups. This schedule provides weekly full backups for the most recent four weeks, while the oldest full backup reaches back a minimum of six months. In addition, the six most recent incremental backups are retained, providing daily restore points for the past week.
Are employee devices encrypted?
Yes. All managed endpoints have full disk encryption.
Do employees use managed devices?
Yes. OTRS employees use centrally managed Linux and macOS devices.
Do you operate according to Zero Trust principles?
Yes. Access decisions are based on verified identities, device compliance and least privilege.
Do you maintain cyber insurance?
Yes. OTRS maintains cybersecurity insurance as part of its risk management strategy.
How can security researchers contact OTRS?
Via security@otrs.com. You will find the PGP key in the published security.txt information.