Secure by design.
A tool that reaches into SAP, databases and servers must be at least as well protected as the systems it looks after. These measures are built in for every customer, not sold as an extra.
Built in for every customer
Your own environment
A separate OPS4 instance per customer: its own application, database and encryption keys. Secrets are stored encrypted and never shown again.
Who gets in
Multi-factor authentication, an optional allowlist of locations checked on every request, and rights per user group. Running an automation is a separate right.
Everything recorded
An audit trail of every change: who, what, when and from where. Sealed in a hash chain, countersigned outside the instance and kept for two years.
Signed agent updates
Agents only connect outward. Before installing an update, an agent checks its signature against the OPS4 release registry and refuses it if it does not match.
Automation under your control
Off by default and allowed twice: when the agent is installed and per server. Every job passes an approval step and is logged step by step.
Write-once log archive
Optional: the logs of your servers and devices in an archive nobody can change or delete before the retention ends. Tripwires, gap detection, destruction only by two people.
Private Mode: OPS4 behind your own tunnel
For organisations that want no internet-facing access at all. You get a dedicated OPS4 instance in its own network segment in our European datacenter, reachable only through an IPsec site-to-site tunnel from your network.
One way in
Only HTTPS through the tunnel, from the subnets you agree with us. From the internet there is nothing to see.
Your servers need no internet
Agents, the Worker and the log archive all deliver through the tunnel. Even the signature check on agent updates runs via a licence proxy in your segment.
Connections start on your side
OPS4 opens nothing into your network, apart from exceptions you choose yourself, such as your own mail relay.
Outbound: default deny
Your instance only reaches a fixed list of destinations agreed with you. Everything else is refused and logged.
Wallboards and the phone app outside your network work through an optional read-only relay that OPS4 feeds and that has no way back in.
Downloads
For your security officer, your network team and your audits.
See it on your own landscape, not on a demo environment
Request a demo and we set up your own cloud instance in Europe for you. Install the agent, approve the host, and your first servers are on screen within half an hour. Without opening your firewall.