Product controls
OTS applies workspace and operation authorization, protected sessions/tokens, scoped Mobile requests, encrypted transport, upload controls, audit records, lifecycle guards, secret scanning, dependency auditing, and exact-commit release provenance.
Operational evidence is separated from ordinary collaboration files and is progressively moving to append-only, tamper-evident records and managed object retention.
Customer controls
Use unique accounts, protect devices, review assignments, remove former users, restrict uploaded personal data, verify notifications, and maintain an offline emergency fallback.
Report a suspected vulnerability privately using the instructions in the security policy; never test another customer or live operation.
Production acceptance
Public paid launch requires managed infrastructure, signed Mobile distribution, provider certification, external legal approval, physical-device testing, independent security review, and a controlled launch rehearsal. A local or Quick Tunnel build is not a production release.