OXAA

Secure public endpoints for local development

Security architecture

Security architecture: practical workflow, product behavior, limits, evidence and the exact next step with Oxaa.

Review the evidence

Start free

Fast answer

Security architecture gives the visitor a direct answer, the exact product behavior, the limits that affect the decision and a practical path to verification.

Security architecture answers a trust question with architecture, controls, failure behavior and evidence. It does not rely on a badge, an adjective or a future certification.

Technical details

  • public client, edge, gateway, agent and local service data flow
  • control plane versus live route ownership
  • SNI and exact Host lookup
  • route generation and lease lifecycle
  • target validation
  • credential issuance and revocation
  • failure behavior for unknown, stale or revoked state
  • single-region baseline and explicit region reporting

Route identity and the selected-service boundary

The enrolled device initiates the connection. Locally generated device identity, proof of possession, short-lived route generations and exact-host matching bind the hostname to the current route. Unknown, malformed, revoked or stale ownership fails closed instead of being forwarded to an uncertain destination.

Oxaa publishes only the configured local target. Private-network destinations require explicit authorization, while public, metadata, link-local, multicast and other unsafe destination classes remain blocked by policy.

What Oxaa is — and is not

Oxaa is development connectivity for a selected local HTTP or HTTPS service while the enrolled device and authenticated route are live. It is not application hosting, a general VPN, a forward proxy, permanent production deployment, raw TCP/UDP tunneling, arbitrary TLS passthrough, a CDN/WAF replacement or a production webhook delivery platform.

Complete the next real step

Continue with Review the evidence when the current product, plan and country support that action. Use Start free to review the exact technical, trust or support path before committing.

oxaa login
oxaa http 3000

Secure public endpoints for local development

Security architecture

Review the evidence