Minimize the exposed action
Each tool should perform a defined business operation instead of exposing an entire system surface.
Security
Oitools.ai STUDIO is designed to reduce invisible access paths and give enterprises a defined control boundary between AI and operational systems.
Every deployment is designed around these control areas. Request the full, current control matrix as part of a security review.
Identity
Sign in through your existing identity provider — SSO, OIDC, SAML or OTP.
Authorization
Every call is enforced by user, role and tool — no blanket access.
Agent/client identity
Every call is attributed to the AI client or agent that made it.
Secrets
System credentials are stored and managed server-side — out of the prompt and the agent.
Encryption
All traffic is encrypted with TLS; at-rest encryption is set to your deployment requirements.
Data retention
You decide what is retained — logs, prompts and results — and for how long, including deletion.
Model training
Your data is never used to train models.
Audit
Every call is logged — who, which tool, which system and the outcome — with field masking, retention and export.
Isolation
Tenant- and environment-level isolation between customers.
Network
Inbound and outbound controls and private connectivity to your systems.
Availability
Health checks, backups and recovery — with an availability SLA per deployment.
Vulnerabilities
Ongoing dependency management, scanning and patching.
Incident handling
A defined reporting path and response process for security incidents.
| Area | What it covers |
|---|---|
| Identity | Sign in through your existing identity provider — SSO, OIDC, SAML or OTP. |
| Authorization | Every call is enforced by user, role and tool — no blanket access. |
| Agent/client identity | Every call is attributed to the AI client or agent that made it. |
| Secrets | System credentials are stored and managed server-side — out of the prompt and the agent. |
| Encryption | All traffic is encrypted with TLS; at-rest encryption is set to your deployment requirements. |
| Data retention | You decide what is retained — logs, prompts and results — and for how long, including deletion. |
| Model training | Your data is never used to train models. |
| Audit | Every call is logged — who, which tool, which system and the outcome — with field masking, retention and export. |
| Isolation | Tenant- and environment-level isolation between customers. |
| Network | Inbound and outbound controls and private connectivity to your systems. |
| Availability | Health checks, backups and recovery — with an availability SLA per deployment. |
| Vulnerabilities | Ongoing dependency management, scanning and patching. |
| Incident handling | A defined reporting path and response process for security incidents. |
ISO 27001 certified
Our information security management is audited and certified to the ISO 27001 standard.
Each tool should perform a defined business operation instead of exposing an entire system surface.
Prompts and desktop configuration should not contain reusable downstream credentials.
The execution path should retain enough verified identity context to support access decisions and audit.
Treat tool inputs, AI-generated values and downstream responses as untrusted until validated.
MCP and agent security evolve quickly. Tool definitions, dependencies and controls require active lifecycle management.