oolak / Features / Security and deployment
Security and deployment

Your data never leaves your building.

oolak runs entirely on your own servers, including networks with no internet connection at all. Access is controlled down to the team level, and every action anyone takes is recorded.

A home page that shows where you stand today.

Runs on your servers

Nothing is sent to a cloud service, which keeps you in line with KVKK and GDPR.

Everyone sees their own

Each person sees only the teams, sites and groups they are responsible for.

Every action recorded

Who did what and when is written to an audit log your SIEM can read.

Security and deployment

What's included

  • It installs on networks with no internet access, and every file it needs ships with it.
  • Installation uses Docker Compose or ready-made images, and a wizard handles the first setup.
  • Files are stored in your own S3 or in the bundled storage, optionally as a high-availability cluster.
  • Isolated networks are reached through a proxy or a gateway in the DMZ.
  • Updates wait for running jobs to finish and take a backup first.
  • Roles are defined in a permission matrix by a super administrator.
  • Sign-in works with LDAP, Active Directory, SAML 2.0 and OIDC, and can be limited to SSO only.
  • Multi-factor authentication uses an authenticator app, an e-mail code or recovery codes.
  • Approvals ask for multi-factor authentication again.
  • Auditors get read-only accounts that expire on a set date.
  • API tokens are limited by scope and rate.
  • The interface can carry your own brand.

See oolak on your own data in 14 days.

We install oolak in your environment, connect your tools and show you your real risk picture. You keep everything it finds.

Start a free 14-day trial → Try the live demo
For engineers

Technical details

What does the stack look like?
A web application and background workers, PostgreSQL, Redis, S3-compatible object storage and Grafana, behind nginx with TLS. Only nginx is exposed to the network.
How is outbound traffic protected?
Every connector call goes through a transport that supports proxies, gateways and custom certificate authorities, and checks each request against loopback, link-local and cloud metadata addresses.
What does the audit log contain?
Every page view and action with actor, time, target, outcome and source address. Secrets are masked, and each event is written to the database and as an RFC 5424 syslog line ready for Splunk or any SIEM.