oktsec / Cloud

Know where your agent policy is applied.

Publish signed policies, see which systems have applied them, and investigate missing or mismatched evidence. Prepare policy and workstation evidence for compliance reviews. Enforcement stays in your environment.

  • Signed policy releases
  • System-level adoption
  • Verified evidence
From policy to proof

Published is not the same as applied.

Your team restricts a tool for a group of systems. Publishing the change does not tell you whether every system is using it. Cloud compares the expected assignment with each node’s evidence so you can find the systems that still need attention.

  1. 01

    Publish the intended policy

    Define the protections and access for a group of systems. Cloud signs and publishes the release.

    Desired state
  2. 02

    Apply it in your environment

    The node retrieves and verifies the policy, applies it locally and reports its state.

    Reported state
  3. 03

    Check adoption against evidence

    Cloud compares the expected assignment with returned evidence and surfaces differences.

    Verified adoption

Know what the next action should be.

What Cloud showsWhat it meansWhat your team does next
Not configuredWhat it meansA system has no policy assignment.Next actionAssign the policy that matches its workflow.
Awaiting evidenceWhat it meansThe expected state has not been confirmed.Next actionCheck enrollment, reporting and local application.
Needs reviewWhat it meansEvidence is stale, different or unverified.Next actionInspect the system and resolve the specific mismatch.
VerifiedWhat it meansThe reported evidence matches the expected policy.Next actionReview ongoing changes and evidence freshness.
One operating view

The questions your security team needs answered.

Move from a policy or alert to the system, owner and evidence behind it.

Systems & ownership

Which systems report, who owns them and which need attention.

Connection state, assigned policy and latest evidence by system.

Policy lifecycle

Which policy should run, and which version was actually reported.

Signed releases, assignment, distribution and verification state.

Agents & tools

Which agent clients, MCP tools and capabilities the nodes report.

Inventory tied to the reporting system and its available evidence.

Requests & changes

Which held actions or changed tool descriptions need a decision.

Review the reported context, approve or reject, and follow the next sync.

Activity & reports

What happened and whether the evidence supports the expected policy.

Trace decisions, inspect verification state and review policy reports.

Team access

Who can manage policy and resolve reviews.

Organization membership and role-based access to the console.

A clear operating boundary

Manage centrally. Enforce locally.

Cloud coordinates the rollout and review. Oktsec Node makes the local decision before a routed request reaches a tool.

Oktsec Cloud

Policy and operating evidence.

  • Publish signed policy and track adoption.
  • Review system state, exceptions and reports.
  • Coordinate security and engineering decisions.
Your environment

Requests and local enforcement.

  • Retrieve and verify the assigned policy.
  • Check routed requests before execution.
  • Sign evidence and report it back.

The node initiates the connection: policy in, evidence out. No inbound control channel or remote shell.

Review the deployment architecture
Review with context

A tool changed. Who decides what happens next?

An approved MCP tool can change its description or input schema. Cloud brings the reported change into review with its system and prior approved version.

Approve the reviewed change.

The decision is bound to the reviewed content. The environment applies the approval on its next sync.

Keep the change blocked.

Retain the previously approved version and investigate the change with the team that owns the system.

EVIDENCE FOR COMPLIANCE

Agent security evidence,
ready for review.

Prepare evidence for SOC 2, ISO 27001 and internal reviews from the observations reported by your systems.

Workstation baselineSystems, owners and observed security controls.CSV

Review eight checks: seven host observations from Node and device ownership recorded in Cloud. Each record includes the system, owner, control and observation date.

  • Anti-malware presence and reported provider
  • Full-disk encryption
  • Screen lock enabled
  • Password required on unlock
  • Screen lock within 15 minutes
  • Automatic security updates
  • Known password manager installed
  • Device inventoried and assigned to an owner

Enable baseline reporting for the workstations in scope. Unsupported or unreadable checks remain unobserved; non-applicable systems are excluded. These checks are not the complete SOC 2 control set.

Policy review reportsPolicy state, exceptions and history for a review period.Markdown

Review coverage, policy state, exceptions, activity and changes for a selected group over 30, 90, 180 or 365 days. Report sections reference relevant SOC 2 and ISO 27001 controls.

Action and audit recordsRecorded activity, administrative changes and signed evidence.CSV / JSON

Export recorded activity and administrative changes. Signed action-evidence bundles allow the reviewer to verify node identity, signatures and the included action lifecycle. Verification establishes record integrity, not complete coverage of the environment.

Organization owners can also export a ZIP of systems, policies, members, alerts and audit/activity records. Its manifest identifies export limits.

Use the workspace you already have.

Review the scope and files, then upload the evidence to your compliance platform or auditor workspace.

Manual upload · No native connector or automatic sync
Third-party compliance platforms
VantaDrata
YOUR FIRST ENVIRONMENT

Start with the systems you want to govern.

Connect a defined group, assign its policy and review the evidence returned by each node. Expand as your team confirms coverage.

Explore ways to get started
Before you connect

Cloud questions.

How is Cloud different from Control?

Cloud manages policy publication, system adoption, evidence and review across your organization. Oktsec Control applies the configured policy to routed agent requests locally. Cloud is outside the tool execution path.

Does publishing a policy mean every system has applied it?

No. Cloud distinguishes the desired policy from the state reported by each node. Adoption is checked against returned evidence. A missing, stale, different or unverified report requires review.

What data reaches Cloud for approvals?

Central quarantine review includes credential-redacted message content. Step-up approval review includes full tool arguments. Routine activity and action-receipt exports use reduced metadata or hashes; agree on reviewer access and data handling before rollout.

Does Cloud need inbound access to our systems?

Nodes initiate outbound connections to retrieve signed policy and send evidence. Cloud does not open a remote shell or execute commands on the node. Deployment requirements are agreed for the environments in scope.

What can our team review centrally?

Connected systems and their owners, policy releases and adoption, reported agent and tool inventory, held requests, changed tool descriptions, activity and policy reports. Available context depends on what each configured node reports.

What evidence can we use for compliance?

Cloud organizes workstation baseline observations, policy reports and exportable activity. Reports reference relevant SOC 2 and ISO 27001 controls. Use exports in your auditor workspace or upload them as custom evidence to a compliance platform.

Can we start with a small deployment?

Yes. Start with one workflow and a defined group of systems. Agree on ownership, policy, connection requirements and evidence before expanding the rollout.

Start with one policy and the systems that need it.

Manage the policies and evidence for your connected systems. Request platform access, or explore how Node fits into your environment. Assessment and deployment support are optional services.