Oxaa
Pricing
EnglishDeutschPortuguês (Brasil)日本語FrançaisРусский
Sign inDownload→
  1. Localhost. Online. Without opening your network.
  2. Privacy notice

Secure public endpoints for local development

Privacy notice

Privacy notice: practical workflow, product behavior, limits, evidence and the exact next step with Oxaa.

Technical details

  • operating entity and roles
  • data categories and purposes
  • legal bases where applicable
  • cookies, local storage and consent
  • public traffic, local Inspector and operational data distinctions
  • billing, support and abuse records
  • subprocessors, transfers and locations
  • retention and deletion
  • rights and request process
  • security contact and complaints
  • effective date and changes

How traffic and Inspector data are handled

Oxaa's public edge terminates public HTTPS so it can resolve the exact hostname, identify the current authenticated route and forward the request. The session between the enrolled device and Oxaa is encrypted; the selected local service receives the request through that session.

Oxaa retains bounded account, route, usage, security, billing, support and diagnostic metadata required to operate and protect the service. Inspector body capture is a separate, explicit debugging action: the bounded request or response body copy shown by the local Inspector remains on the developer device and can be redacted, deleted or allowed to expire. Public traffic still has to be processed by the edge, so the accurate claim is local Inspector copies-not “Oxaa cannot see traffic.”

Security overview
Security overview→Security architecture→Data handling and retention→Trust center→Signed software and supply chain→Vulnerability disclosure→Subprocessors and data locations→DPA and procurement→Service status and incidents→Availability, regions and country eligibility→Acceptable Use Policy and abuse response→Cookie and tracker notice→Terms of service→Legal notice / company disclosure→
Oxaa
EnglishDeutschPortuguês (Brasil)日本語FrançaisРусский
Product overviewProduct overviewHow Oxaa worksLocal request inspectorSecure developer endpointsProtocols and limitsCustom domainsTeams and workspace governancePricing and packaging
Use cases hubUse cases hubWebhook developmentOAuth callbacksPreview environmentsMobile and cross-device testingWebSocket and Server-Sent EventsAgency and client previewsCloud automation and tool callbacks
Documentation homeDocumentation homeQuickstart: first external requestDownload and signed installationIntegration guides hubFramework and runtime guides hubCLI referenceConfiguration and multi-route environmentsTroubleshooting and error hub
Compare alternatives hubCompare alternatives hubOxaa vs ngrokOxaa vs Cloudflare TunnelOxaa vs Tailscale FunnelOxaa vs Microsoft Dev TunnelsOxaa vs PinggyOxaa vs LocalCan
Security overviewSecurity overviewSecurity architectureData handling and retentionTrust centerSigned software and supply chainVulnerability disclosureService status and incidentsAvailability, regions and country eligibility
Resources and learning hubResources and learning hubLearn / editorial indexExamples and templatesCustomer storiesOriginal research and benchmark hubVideos and workshopsCommunityChangelog
About OxaaAbout OxaaSupport and contactLegal notice / company disclosure
Privacy noticePrivacy noticeTerms of serviceCookie and tracker noticeAcceptable Use Policy and abuse responseSubprocessors and data locationsDPA and procurementAccessibility statement