Oxaa
Pricing
EnglishDeutschPortuguês (Brasil)日本語FrançaisРусский
Sign inDownload→
  1. Localhost. Online. Without opening your network.
  2. Security overview
  3. Trust center

Secure public endpoints for local development

Trust center

Trust center: practical workflow, product behavior, limits, evidence and the exact next step with Oxaa.

Fast answer

Trust center answers a trust question with architecture, controls, failure behavior and evidence. It does not rely on a badge, an adjective or a future certification.

Technical details

  • security overview
  • data handling
  • signed software and supply chain
  • vulnerability disclosure
  • status and incident history
  • subprocessors and data locations
  • DPA and procurement
  • acceptable use and country availability

Route identity and the selected-service boundary

The enrolled device initiates the connection. Locally generated device identity, proof of possession, short-lived route generations and exact-host matching bind the hostname to the current route. Unknown, malformed, revoked or stale ownership fails closed instead of being forwarded to an uncertain destination.

Oxaa publishes only the configured local target. Private-network destinations require explicit authorization, while public, metadata, link-local, multicast and other unsafe destination classes remain blocked by policy.

What Oxaa is - and is not

Oxaa is development connectivity for a selected local HTTP or HTTPS service while the enrolled device and authenticated route are live. It is not application hosting, a general VPN, a forward proxy, permanent production deployment, raw TCP/UDP tunneling, arbitrary TLS passthrough, a CDN/WAF replacement or a production webhook delivery platform.

Security overview
Security overview→Security architecture→Data handling and retention→Signed software and supply chain→Vulnerability disclosure→Subprocessors and data locations→DPA and procurement→Service status and incidents→Availability, regions and country eligibility→Acceptable Use Policy and abuse response→Privacy notice→Cookie and tracker notice→Terms of service→Legal notice / company disclosure→
Oxaa
EnglishDeutschPortuguês (Brasil)日本語FrançaisРусский
Product overviewProduct overviewHow Oxaa worksLocal request inspectorSecure developer endpointsProtocols and limitsCustom domainsTeams and workspace governancePricing and packaging
Use cases hubUse cases hubWebhook developmentOAuth callbacksPreview environmentsMobile and cross-device testingWebSocket and Server-Sent EventsAgency and client previewsCloud automation and tool callbacks
Documentation homeDocumentation homeQuickstart: first external requestDownload and signed installationIntegration guides hubFramework and runtime guides hubCLI referenceConfiguration and multi-route environmentsTroubleshooting and error hub
Compare alternatives hubCompare alternatives hubOxaa vs ngrokOxaa vs Cloudflare TunnelOxaa vs Tailscale FunnelOxaa vs Microsoft Dev TunnelsOxaa vs PinggyOxaa vs LocalCan
Security overviewSecurity overviewSecurity architectureData handling and retentionTrust centerSigned software and supply chainVulnerability disclosureService status and incidentsAvailability, regions and country eligibility
Resources and learning hubResources and learning hubLearn / editorial indexExamples and templatesCustomer storiesOriginal research and benchmark hubVideos and workshopsCommunityChangelog
About OxaaAbout OxaaSupport and contactLegal notice / company disclosure
Privacy noticePrivacy noticeTerms of serviceCookie and tracker noticeAcceptable Use Policy and abuse responseSubprocessors and data locationsDPA and procurementAccessibility statement