Trust & Security
Last updated: August 2026
OKTee is a B2B SaaS platform designed to manage retail operations. This page provides the main information required by technical, security, legal and procurement teams to assess the security, hosting and compliance measures implemented around OKTee.
OKTee processes only the data required to provide its services, including OKTee Operations, OKTee Finance and OKTee Marketing.
Platform availability
Check platform availability, ongoing incidents and maintenance history.
→ oktee.instatus.com
1. Infrastructure and hosting
OKTee relies on cloud infrastructure designed to host core customer data in Europe where the configuration allows it, while using certain technical providers that may involve controlled processing or transfers outside the European Union.
- Public website: Framer for www.oktee.io, legal pages and public content.
- Application interface: Vercel when this infrastructure is used for the OKTee application.
- Database: Neon managed PostgreSQL, hosted in the European Union where the configuration allows it.
- Automated processing: Railway for workers, synchronizations and server-side tasks.
- Orchestration: Inngest for certain asynchronous tasks and application workflows.
- Monitoring: Sentry for error detection and technical diagnostics.
- Complementary cloud services: Amazon Web Services depending on technical needs and enabled modules.
- AI-assisted analysis: OpenAI for certain Operations, Finance or Marketing features requiring AI-assisted analysis.
- Product-page monitoring: Rainforest API for certain public Amazon signals required by OKTee Marketing.
- Status page: Instatus for publishing service availability and incidents.
Sources of processed data
- Connected retail platforms: at present, direct platform connections mainly concern Amazon Vendor Central through official Amazon APIs.
- Customer systems: ERP, WMS, customer APIs, product catalogs and other customer-authorized systems.
- Data entered or imported into OKTee: information, approvals, documents, supporting evidence or operations required for the workflows used by the customer.
OKTee Finance may process operations relating to different retailers without requiring a direct connection to each of their systems. Data may come from OKTee, customer systems or platforms that are actually connected.
2. Data encryption
| Level | Measure applied |
|---|---|
| Data in transit | TLS 1.2 minimum for communications between users, OKTee and authorized external APIs. |
| Data at rest | Encryption at rest according to the mechanisms provided and configured on the infrastructure used. |
| Backups | Backup and recovery mechanisms according to the infrastructure services used and their configuration. |
| Passwords | Passwords are never stored in plain text and are protected using appropriate hashing mechanisms. |
| Secrets and tokens | Secrets, technical keys and access tokens are stored securely and separately from application code. |
3. Access control and authentication
- Role-based access control, RBAC: access to data and features is limited according to each user’s role.
- Least privilege: each user only accesses the information required for their responsibilities.
- Multi-tenant isolation: each customer’s data is logically isolated.
- Internal access: OKTee team members access customer data only when necessary to provide, maintain, secure or support the service.
- Traceability: important actions may be logged to support technical, operational or security monitoring.
- Secure sessions: user sessions are protected through appropriate authentication and expiration mechanisms.
- MFA: multi-factor authentication may be used depending on the authentication method and security rules applied to the organization.
- SSO: when users sign in through an identity provider such as Google or Microsoft, the provider’s security and MFA mechanisms apply.
4. Amazon SP-API connection security
OKTee primarily connects to Amazon Vendor Central accounts authorized by its customers through the official Amazon APIs, SP-API.
For certain OKTee Marketing features, OKTee may also collect public Amazon product-page signals through specialized providers when the required data is not available or sufficient through official Amazon APIs.
- Connections to Amazon accounts are initiated by the customer through the official Amazon authorization flow.
- OKTee never directly asks customers for their Amazon credentials.
- Amazon access tokens are stored securely.
- OKTee access may be revoked by the customer from their Amazon interface where this option is available.
- Requested permissions are limited to the roles required for the services being used.
- OKTee does not sell Amazon data or use it for advertising purposes.
5. Amazon data processed
Depending on the services used and permissions granted by the customer, OKTee may process certain data from Amazon Vendor Central.
- order data and statuses;
- order acknowledgements and responses;
- shipment data;
- inventory and availability data;
- catalog data;
- pricing and offer data;
- Brand Analytics data, when available and authorized;
- financial data, invoices, payments, deductions, discrepancies, shortages or chargebacks where the corresponding permissions are granted.
6. Data from customer systems
Depending on the modules enabled and connectors authorized, OKTee may process data from ERP, WMS, product catalogs, internal APIs or other customer systems.
This data may be used to reconcile retail-platform flows with internal references, inventory, logistics rules, automation settings, accounting data or financial reconciliation data.
7. Network and application security
- HTTPS: communications between users and the application are protected through HTTPS.
- Application protection: the infrastructure used by OKTee includes protections against common attacks.
- Security headers: security headers may be applied to reduce browser-related risks.
- Environment separation: production, staging and development environments are separated.
- Secrets management: identifiers, API keys and credentials are not stored in code repositories.
8. Security incident management
OKTee maintains an incident response procedure covering detection, analysis, remediation and communication with affected customers where necessary.
- incident detection and qualification;
- assessment of potential impact;
- containment and corrective measures;
- notification of affected customers where customer data is impacted;
- reasonable assistance to customers in meeting regulatory obligations;
- post-incident analysis and improvement of security measures.
In the event of a personal data breach affecting data processed on behalf of a customer, OKTee aims to inform the customer within 48 hours after becoming aware of the incident, subject to the information reasonably available at that stage.
Where applicable law requires notification to a supervisory authority, the entity acting as data controller remains responsible for that notification, including the GDPR 72-hour deadline where it applies.
Incidents involving Amazon data are handled in accordance with the security and notification requirements applicable to Amazon SP-API.
For any security incident or suspected data breach: security@oktee.io
9. Secure development practices
- Change review: significant application changes are reviewed before production deployment.
- Dependency management: OKTee monitors known vulnerabilities in application dependencies.
- Secrets and credentials: identifiers, API keys and passwords must not be stored in code repositories.
- Vulnerability remediation: critical vulnerabilities are handled as a priority.
- Application monitoring: technical errors are monitored to detect malfunctions quickly.
10. Third-party vendors and data transfers
OKTee uses technical providers to host, synchronize, monitor, secure and improve its services. Certain providers may involve transfers outside the European Union. Where required, these transfers are covered by appropriate contractual safeguards.
| Provider | Main purpose | Region / note |
|---|---|---|
| Framer | Public website, legal pages and public content | Global infrastructure |
| Vercel | OKTee application interface | Global infrastructure |
| Neon | PostgreSQL database | European Union where configured accordingly |
| Railway | Workers, synchronizations and automated processing | European Union where configured accordingly |
| Inngest | Workflow orchestration | Cloud infrastructure |
| Sentry | Application monitoring and diagnostics | United States with appropriate contractual safeguards |
| OpenAI | AI-assisted analysis for certain OKTee features | United States with appropriate contractual safeguards |
| Rainforest API | Collection of public Amazon product-page signals | Provider infrastructure |
| Amazon Web Services | Complementary cloud services | Depending on configured services and regions |
| Instatus | Status page and service-availability communications | Provider infrastructure |
The full list is available on the Third-party vendors page.
11. Compliance
| Framework | Application |
|---|---|
| GDPR | Data protection, purpose limitation, minimization and processing-security principles. |
| Article 28 GDPR | OKTee may act as a processor and provide a DPA where required. |
| Amazon SP-API | Amazon data is used only in connection with services authorized by the customer. |
| Standard Contractual Clauses | Used where required to cover certain transfers outside the European Union. |
| Data reversibility | Data return or deletion mechanisms according to applicable contractual terms. |
| SOC 2 | Compliance roadmap in progress. |
12. Documents available upon request
- Security one-pager;
- OKTee DPA;
- responses to security or vendor questionnaires.
Contact: legal@oktee.io
13. Vulnerability reporting
If you discover a security vulnerability in our systems, please report it responsibly to security@oktee.io.
OKTee aims to acknowledge vulnerability reports within 48 hours and keep the reporter informed of their handling.
14. Security contact
6 rue des Berceaux, 95160 Montmorency, France
Security: security@oktee.io
Legal: legal@oktee.io
Privacy: privacy@oktee.io
See also: Privacy Policy · Third-party vendors · DPA · Amazon Integration
Security Policy
Last updated: 2026
Protecting customer data is a top priority at OKTee. This page outlines the technical and organizational measures implemented to safeguard the confidentiality, integrity, and availability of data processed on our platform.
OKTee only processes the data required to deliver its services, specifically OKTee Ops, OKTee Marketing, OKTee Logistique, and future Finance modules.
1. Infrastructure & Hosting
OKTee is built on cloud infrastructure designed to host core customer data in Europe whenever configuration permits, while utilizing select technical sub-processors whose services may involve compliant data transfers outside the EU.
- Marketing Website, Legal Pages & Public Content: Hosted on Framer. The oktee.io site is used to showcase OKTee services, publish legal agreements, and share informational content with customers, prospects, and partners. The marketing website does not store any operational Amazon data from customers.
- Application Interface: Hosted on Vercel when this infrastructure is deployed for the OKTee application. The interface primarily serves to render the application for authorized users. Core backend processing and primary customer data storage are not handled on Vercel. Any transfers outside the European Union are governed by appropriate contractual safeguards.
- Customer Database: Neon, a managed PostgreSQL service, hosted in the European Union where configuration permits. This database stores customer records, user accounts, catalog details, order histories, and the Amazon data required to run the platform.
- Background & Automated Processing: Railway is used to run sync workers, background processes, and server-side automated tasks. These workers read, process, and route data required for the customer's active modules.
- Workflow Orchestration: Inngest is used to trigger and monitor asynchronous tasks, processing queues, scheduled runs, and application workflows.
- Application Performance Monitoring: Sentry is used to detect application errors, diagnose performance anomalies, and improve overall service reliability. OKTee applies strict data scrubbers to filter out sensitive details where applicable.
- AI-Assisted Analysis: OpenAI may be leveraged for specific features in OKTee Marketing. This only occurs when these features are explicitly enabled by the customer, and only for data strictly relevant to product performance analysis.
- Product Page Monitoring: Rainforest API may be utilized to capture public signals from Amazon product detail pages (PDPs) required for OKTee Marketing—such as live content, buybox pricing, availability, or offer signals—when this data is unavailable or incomplete via official Amazon APIs.
Core customer data is hosted in Europe where configuration permits. The oktee.io marketing site is hosted by Framer and does not store operational Amazon customer data. Certain technical subprocessors may involve compliant data transfers outside the European Union. OKTee restricts data shared with each sub-processor to the absolute minimum necessary.
Technical partners utilized by OKTee are governed by standard contractual terms, DPAs, or transfer mechanisms where required.
2. Data Encryption
| Tier | Standard Applied |
|---|---|
| Data in Transit | TLS is enforced for all communications between users, the OKTee platform, and authorized external APIs. |
| Data at Rest | Encryption of stored data where supported or mandated by the hosting infrastructure providers. |
| Backups | Backups are protected and secured utilizing native mechanisms provided by our hosting partners. |
| Passwords | OKTee never stores cleartext passwords. Authentication protocols utilize industry-standard hashing algorithms. |
| Secrets & Tokens | API keys, technical secrets, and access tokens are securely managed and never hardcoded in source repositories. |
3. Access Control
- Role-Based Access Control (RBAC): Access to data and features is strictly restricted based on assigned user roles.
- Principle of Least Privilege: Users are granted only the access permissions required to perform their specific business functions.
- Multi-Tenant Isolation: Customer data is logically segregated. Cross-tenant access is strictly blocked.
- Internal Access: OKTee team members only access customer data when explicitly required for system maintenance, security operations, or customer support request resolution.
- Audit Trails: Key system events and actions are logged for technical, operational, and security review.
- Secure Sessions: User sessions are protected by industry-standard authentication flow controls and automated timeouts.
4. Amazon Connection & SP-API Security
OKTee integrates with authorized Amazon Vendor Central accounts via the official Amazon Selling Partner API (SP-API). For specific OKTee Marketing features, OKTee may also crawl public signals from Amazon PDPs using specialized data partners when these details are not available via official Amazon APIs.
- Connections to Amazon Vendor Central are initiated by the customer using Amazon’s official OAuth authorization flow. OKTee never requests, stores, or handles your raw Amazon login credentials.
- Amazon access tokens are stored securely and are never exposed to end-users.
- OKTee API access can be revoked by the customer at any time directly from their Amazon Seller Central/Vendor Central partner console.
- Requested permissions are strictly limited to the specific API roles needed to run active OKTee modules.
- OKTee does not resell Amazon data, share it for advertising purposes, or utilize it outside of delivering authorized customer services.
5. Processed Amazon Data
Depending on the active modules and the access permissions granted, OKTee processes specific operational data from Amazon Vendor Central:
- Order data
- Purchase order statuses
- Order acknowledgements and confirmations
- Shipping and routing details
- Inventory levels and availability
- Catalog attributes
- Pricing and buybox offer signals
- Brand Analytics data (where available and authorized)
- Financial data, including invoices, payments, deductions, shortages, or chargebacks (where relevant roles are enabled)
6. External Data Systems
OKTee may also process auxiliary data imported from authorized customer systems.
Currently, this primarily includes the customer's master product catalog, ingested from their ERP via the OKTee API or the customer's native API. This catalog enables the mapping of Amazon purchase orders to internal SKUs, inventory allocation rules, fulfillment logic, and automated workflows within OKTee Command Center.
For future Finance modules, OKTee may ingest other billing details held by the customer— specifically ERP, accounting, invoicing, payment, or settlement data—only when the module is explicitly activated and authorized by the customer.
7. Network Security
- HTTPS: All data in transit between the user and the platform is protected via secure HTTPS.
- Application Firewalls: OKTee’s cloud environments leverage platform protection layers designed to block common web attacks, including injections, unauthorized access attempts, and traffic abuse.
- Security Headers: Modern security headers are enforced to protect users from browser-side threats.
- Environment Segregation: Production, staging, and development environments are completely isolated from each other.
- Secrets Management: API keys, infrastructure credentials, and security secrets are stored using secure environment managers and never committed to code.
8. Security Incident Management
OKTee maintains an Incident Response Plan covering the identification, containment, mitigation, and communication of potential security events.
- Detection and triage of security anomalies
- Assessment of scope and operational impact
- Containment and remediation actions
- Proactive notification to affected customers when an incident impacts customer data
- Reasonable assistance to help customers meet their own regulatory disclosure obligations
- Post-incident review and preventive security hardening
If you suspect any unauthorized access or security breach involving your Amazon or OKTee data, please contact us immediately at: privacy@oktee.io
9. Secure Development Practices
- Code Reviews: Significant code changes undergo peer review prior to production deployment.
- Dependency Scanning: OKTee monitors dependencies for known vulnerabilities and security alerts.
- Secrets Detection: Automated checks ensure API keys, certificates, or credentials are never checked into git repositories.
- Vulnerability Remediation: Critical security issues are prioritized and addressed on an expedited cycle.
- Performance Logging: Runtime errors are tracked using secure tools to rapidly identify and address anomalies.
10. Authentication & Password Security
- User accounts are accessed using secure authentication protocols.
- Passwords are hashed; plain text values are never stored.
- Internal OKTee platform access is restricted to authorized operations staff.
- Sharing user credentials among team members is strictly prohibited.
- Advanced authentication layers can be activated based on organization and enterprise tenant requirements.
11. Sub-Processors & Data Transfers
OKTee partners with technical subprocessors to deliver core services, including marketing site hosting, application hosting, databases, background sync workers, workflow orchestration, application performance monitoring, AI tools, or public PDP monitoring.
Certain partners may process data outside the European Economic Area. Where required, such transfers are protected by standard contractual frameworks, specifically European Commission Standard Contractual Clauses (SCCs).
Core Technical Sub-Processors
| Sub-Processor | Service Provided | Data Region | Safeguards |
|---|---|---|---|
| Framer | Hosting and delivery of the OKTee marketing site, legal terms, and public resources. | Global infrastructure; potential data transfers outside the EU. | Applicable DPA and standard terms, with transfer mechanisms where needed. The marketing site does not store operational Amazon customer data. |
| Vercel | Hosting and delivery of the OKTee application UI. | Global infrastructure; potential data transfers outside the EU. | Applicable DPA and standard terms, with transfer mechanisms where needed. Primary storage and core data processing do not occur on Vercel. |
| Neon | Managed PostgreSQL database engine used by OKTee. | European Union (where configuration permits). | Applicable DPA and standard terms, with transfer safeguards where needed. |
| Railway | Background processing, sync queues, automated tasks, and worker execution. | European Union (where deployment configuration permits). | Applicable DPA and standard terms, with transfer safeguards where needed. |
| Inngest | Workflow orchestration, asynchronous task processing, and job scheduling. | Cloud infrastructure; potential data transfers outside the EU. | Applicable DPA and standard terms, with transfer safeguards where needed. |
| Sentry | Application error tracking, diagnostics, and performance monitoring. | United States, under applicable contractual safeguards. | Standard Contractual Clauses (SCCs) in place for cross-border transfers. Data scrubbers applied to filter out sensitive attributes. |
| OpenAI | AI-assisted insights for specific OKTee Marketing features selected by the user. | United States, under applicable contractual safeguards. | Limited strictly to features enabled by the user. Standard Contractual Clauses (SCCs) implemented where required. |
| Rainforest API | Retrieval of public Amazon product detail page signals for OKTee Marketing. | Provider infrastructure; potential data transfers outside the EU. | Contractual partner terms. OKTee prioritizes official Amazon APIs where the necessary data points are available. |
A comprehensive list of our subprocessors is available on the dedicated Subprocessors Page.
12. Compliance & Standards
| Framework | Implementation details |
|---|---|
| GDPR (EU Regulation 2016/679) | OKTee adheres to principles of data protection by design, purpose limitation, data minimization, and secure processing. |
| GDPR Article 28 | OKTee acts as a data processor for its customer tenants and provides a standard Data Processing Addendum (DPA) where applicable. |
| Amazon SP-API Developer Agreement | OKTee accesses and processes Amazon data strictly to deliver services requested by the customer, under permitted API roles. |
| Standard Contractual Clauses | Executed with third parties to govern secure data flows outside of the European Economic Area. |
| Data Portability | OKTee supports structured processes for data return or secure deletion in line with our standard service agreements. |
13. Vulnerability Disclosure
If you identify a potential security vulnerability within our platform, please disclose it to us responsibly at: privacy@oktee.io
OKTee is committed to investigating reports thoroughly and addressing critical security concerns on an expedited schedule.
14. Security & Compliance Contact
See also: Privacy Policy · Subprocessors · DPA · Amazon Integration Overview
Signed DPA