SOMETHING CAN ASK. ONLY PEOPLE CAN APPROVE.
Outis puts a physical key between a request and the thing it unlocks. Compromised software can knock, but it can't get in.
A STOLEN SESSION
CAN'T APPROVE
Approval never happens in a browser.
A LEAKED CI TOKEN
CAN'T DEPLOY ITSELF
A token can ask. It can't turn a key.
ONE PERSON ALONE
CAN'T GO ROGUE
When policy says two, the second key is in someone else's hand.
A DISTRACTED TAP
CAN'T SLIP THROUGH
Key, code and cover. Nobody approves by accident.
THE SPEC SHEET.
DEVICE
Keys made on the box, never exported
SHIPPING
Signed OTA updates
SHIPPING
Flash encryption
IN PROGRESS
Secure boot
IN PROGRESS
CONNECTION
Mutual TLS
SHIPPING
Dials out only, nothing listening
SHIPPING
Signed webhooks, replay-protected
SHIPPING
SERVICE
Encryption at rest
SHIPPING
Scoped API keys
SHIPPING
Code guess lockouts, per device
SHIPPING
SSO / SAML
IN PROGRESS
AUDIT
Append-only log, no edit or delete
SHIPPING
Approvals bound to the exact commit
SHIPPING
Authorized and executed, logged separately
SHIPPING