OXAA

Secure public endpoints for local development

Data handling and retention

Data handling and retention: practical workflow, product behavior, limits, evidence and the exact next step with Oxaa.

Review the evidence

Start free

Fast answer

Data handling and retention gives the visitor a direct answer, the exact product behavior, the limits that affect the decision and a practical path to verification.

Data handling and retention answers a trust question with architecture, controls, failure behavior and evidence. It does not rely on a badge, an adjective or a future certification.

Technical details

  • public traffic forwarding
  • account and authentication data
  • route, device and usage metadata
  • billing and support records
  • local Inspector capture
  • redaction, truncation, deletion and expiry
  • retention and deletion table
  • future hosted capture as a separate unshipped feature

How traffic and Inspector data are handled

Oxaa's public edge terminates public HTTPS so it can resolve the exact hostname, identify the current authenticated route and forward the request. The session between the enrolled device and Oxaa is encrypted; the selected local service receives the request through that session.

Oxaa retains bounded account, route, usage, security, billing, support and diagnostic metadata required to operate and protect the service. Inspector body capture is a separate, explicit debugging action: the bounded request or response body copy shown by the local Inspector remains on the developer device and can be redacted, deleted or allowed to expire. Public traffic still has to be processed by the edge, so the accurate claim is local Inspector copies—not “Oxaa cannot see traffic.”

What Oxaa is — and is not

Oxaa is development connectivity for a selected local HTTP or HTTPS service while the enrolled device and authenticated route are live. It is not application hosting, a general VPN, a forward proxy, permanent production deployment, raw TCP/UDP tunneling, arbitrary TLS passthrough, a CDN/WAF replacement or a production webhook delivery platform.

Complete the next real step

Continue with Review the evidence when the current product, plan and country support that action. Use Start free to review the exact technical, trust or support path before committing.

oxaa login
oxaa http 3000

Secure public endpoints for local development

Data handling and retention

Review the evidence