Fast answer
Security overview answers a trust question with architecture, controls, failure behavior and evidence. It does not rely on a badge, an adjective or a future certification.
Technical details
selected local service boundarydevice identity and short-lived credentialsroute generations, exact-host and fail-closed behaviorunsafe-destination policypublic TLS termination and encrypted device sessionlocal Inspector body copies versus operational metadatarevocation, audit, abuse response and shared responsibilitysigned software, vulnerability, status, subprocessors, DPA and limits
Route identity and the selected-service boundary
The enrolled device initiates the connection. Locally generated device identity, proof of possession, short-lived route generations and exact-host matching bind the hostname to the current route. Unknown, malformed, revoked or stale ownership fails closed instead of being forwarded to an uncertain destination.
Oxaa publishes only the configured local target. Private-network destinations require explicit authorization, while public, metadata, link-local, multicast and other unsafe destination classes remain blocked by policy.
What Oxaa is - and is not
Oxaa is development connectivity for a selected local HTTP or HTTPS service while the enrolled device and authenticated route are live. It is not application hosting, a general VPN, a forward proxy, permanent production deployment, raw TCP/UDP tunneling, arbitrary TLS passthrough, a CDN/WAF replacement or a production webhook delivery platform.
