Skip to content
SSO · HIPAA mode · Region-pinned

The platform your security review can approve.

SSO. SAML 2.0. LDAP + Active Directory. HIPAA mode. Full audit export. Region-pinned data. Dedicated SLA. Every enterprise-grade posture your compliance team needs, on top of the same product your operators already use — no separate admin console, no different data model, no bolted-on chatbot.

Identity + SSO

Sign your team in the way your directory already works.

  • SAML 2.0. IdP-initiated + SP-initiated flows. Attribute mapping to roles + teams. Every IdP you'd try (Okta, Entra ID, Google Workspace, Ping, Auth0, JumpCloud, OneLogin).
  • OIDC. Generic OIDC connector for anything not on the SAML list. Discovery URL + client id/secret; audience + scope claim mapping.
  • LDAP + Active Directory. Directory-sourced users, group-sourced roles, nested group flattening. Sync via scheduled worker or event-driven.
  • Passkeys, TOTP 2FA, WebAuthn hardware keys. Force enrolment per role; recovery-code flow; step-up auth for dangerous actions.
  • Impersonation with per-session audit. Support your customer over the phone without borrowing their password. Every impersonated action logs the actor's original identity alongside the impersonated one.
Compliance

Postures your legal team can actually attach a policy to.

SOC 2 Type II — in progress

Underway, not yet certified. Our policy library is available to Enterprise customers today; the auditor's report follows when the audit does.

HIPAA mode

BAA + PHI handling controls turned on org-wide. Encryption at rest + in transit; audit log retention extended; risk assessments quarterly.

GDPR + DPA

Standard-clause DPA + sub-processor list + Art. 20 data export + Art. 17 deletion. EU data-region option.

PCI DSS

Payment card handling routed through PCI-compliant gateways (Stripe / Adyen / Braintree / Razorpay). We never touch or store card numbers.

Audit + observability

Every action, every actor, every input — one immutable log.

  • Every user-performable operation is an action. The action layer is the ONLY write path — UI, AI agent, MCP server, CLI all invoke the same action; all log to the same `audit_log` row.
  • Full audit export. Streaming CSV / JSONL / Parquet per-org export to your SIEM (Splunk / Datadog / Sumologic) via signed URL or S3 sync.
  • Hash-chained rows. Daily SHA-256 chain over the day's audit rows makes retro-editing history detectable.
  • AI actor attribution. Every AI-driven action logs BOTH the operator who delegated + the AI tool that executed. You can filter "everything the AI did last week" or "everything Jane did — including via AI."
  • Impersonation trace. Support-team impersonation sessions log the impersonator + the impersonated + every action + every viewport the impersonator saw.
Data residency + SLA

Region pinning + dedicated SLA + priority support.

  • Region pinning. Choose US, EU, UK, or APAC per-tenant. Data at rest never leaves the region; cross-region replicas opt-in only.
  • Bring your own storage. Pin every byte to your own S3 / R2 / MinIO / B2 / Wasabi / DigitalOcean Spaces / Hetzner / Scaleway bucket. Files never leave your cloud.
  • Custom domains. Host Odexy at `app.yourcompany.com`; per-org branded portals at `portal.yourcompany.com`.
  • Dedicated SLA. 99.9% uptime with financial penalties (starts at 10% credit for downtime under 99.5%). Priority incident escalation with a named CS engineer.
  • Support tiers. Business hours + on-call weekend + 24/7 severity-1 tiers available. Response times: sev-1 within 15 minutes, sev-2 within 2 hours, sev-3 same business day.
Deployment

Cloud, single-tenant, or your own infrastructure.

Multi-tenant cloud

Default. Shared tenancy on our infrastructure; region-pinned; 99.9% SLA. Fastest to onboard.

Single-tenant cloud

Dedicated database + storage + workers, still on our infrastructure. Isolation + BYOB + custom retention.

Self-hosted

Deploy to your own cloud (AWS, GCP, Azure, on-prem). Kubernetes chart + Terraform module. Under evaluation for Enterprise buyers with strict data-locality requirements.

FAQ

The questions your buying committee will ask.

Do you support SAML for our IdP?
Yes — Okta, Entra ID, Google Workspace, Ping, Auth0, JumpCloud, OneLogin, and generic OIDC covers everything else.
Can we get a security-review packet?
Yes — architecture diagram, sub-processor list, DPA and HIPAA BAA, all under NDA, sent within 24h of request. SOC 2 Type II is in progress; we will add the report to the packet when the audit completes rather than before.
Do you handle procurement paperwork?
Yes. Custom MSA, redlines, IT-security questionnaires, vendor onboarding forms. We keep a template library so common clauses close in days, not weeks.
What's Enterprise pricing?
Per-org (not per-seat). Volume-tiered. Every module included; every SSO / audit / compliance affordance included. Sales quotes based on your org size + region + support tier.
How long does onboarding take?
Multi-tenant cloud: same-day. Single-tenant cloud: 3-5 business days. Self-hosted: 2-4 weeks depending on your infrastructure team.
Enterprise

Bring your compliance review.

We keep the packet ready. Sales replies within one business day; a security engineer is on the second call.

Subscribe to the Odexy changelog.

One email every ~2 weeks. Honest product notes, no marketing pitches.

We email you only when there's something honest to say. Unsubscribe in one click.