Otterly AI logo
Otterly AI
Enterprise and security

Otterly AI enterprise security, SSO, SOC 2 and procurement

A procurement-focused review of Otterly AI SAML SSO, roles, SOC 2 and ISO status, audit-log uncertainty, legal terms, data residency, uptime evidence, and Trakkr.

Trakkr editorial teamPublished 2026-08-25
10 min read
Last updated: August 25, 2026

Quick answer

Does Otterly AI meet enterprise security, identity, legal, and procurement requirements?

Otterly AI documents Enterprise SAML 2.0 SSO, three account roles, public privacy material, and downloadable legal terms. It does not currently hold SOC 2 or ISO 27001 certification; its SOC 2 Type II audit has no published date. Customer-visible audit logs, selectable data residency, and a public first-party status history or general uptime SLA are not documented, so regulated buyers need written answers before approval.

Published by Trakkr. Sources checked 2026-08-25.
Evidence: Otterly AI SAML single sign-on setup, Otterly AI pricing and plan comparison, Otterly AI admin, member and viewer roles, Otterly AI terms and conditions, Otterly AI privacy policy and GDPR information, Otterly AI SOC 2 and ISO 27001 status, Otterly AI security and terms indexNot publicly verified. This is a public-documentation finding, not proof that audit records are unavailable in a private Enterprise arrangement. Request scope, retention, export, and event coverage in writing.Not publicly verified. The company is based in Austria and publishes GDPR material, but that does not establish where customer product data is hosted or whether regional residency can be contracted.Not publicly verified. Enterprise contracts may include private service commitments. Buyers should request uptime definitions, exclusions, incident notice, support priority, and service-credit terms.
SOC 2 and ISO 27001
No current Otterly certification; SOC 2 Type II is undated roadmap workEvidence: Otterly AI SOC 2 and ISO 27001 status
Roles
Admin, Member, and ViewerEvidence: Otterly AI admin, member and viewer roles
Audit logs
Customer-visible activity records are not publicly documentedEvidence: Otterly AI security and terms index, Otterly AI admin, member and viewer roles, Otterly AI SAML single sign-on setup, Otterly AI pricing and plan comparisonNot publicly verified. This is a public-documentation finding, not proof that audit records are unavailable in a private Enterprise arrangement. Request scope, retention, export, and event coverage in writing.
Data residency
A buyer-selectable hosting region is not publicly documentedEvidence: Otterly AI security and terms index, Otterly AI privacy policy and GDPR information, Otterly AI terms and conditions, Otterly AI pricing and plan comparisonNot publicly verified. The company is based in Austria and publishes GDPR material, but that does not establish where customer product data is hosted or whether regional residency can be contracted.
Legal package
April 2026 terms and public privacy material; custom Enterprise terms advertisedEvidence: Otterly AI terms and conditions, Otterly AI privacy policy and GDPR information, Otterly AI pricing and plan comparison

Otterly AI procurement evidence checklist

Otterly AI procurement evidence checklist
ControlOtterly AI public evidenceTrakkr public evidenceProcurement conclusion
Vendor SOC 2Not certified; Type II audit is on the roadmap without a dateNo Trakkr-owned SOC 2 certification currently claimedNeither vendor clears a hard company-level SOC 2 requirement todayEvidence: Otterly AI SOC 2 and ISO 27001 status, Security at Trakkr
Enterprise identitySAML 2.0 SSO configured through customer IdP metadataEnterprise lists SAML or OIDC SSO and SCIM provisioningTrakkr documents the broader identity set; test exact IdP behavior in either productEvidence: Otterly AI SAML single sign-on setup, Otterly AI pricing and plan comparison, Trakkr plans and Enterprise controls
Application rolesAdmin, Member, and Viewer with a published permission matrixRole-based access, MFA, row-level isolation, and secure sessionsOtterly's role model is clear; Trakkr publishes more underlying control detailEvidence: Otterly AI admin, member and viewer roles, Security at Trakkr
Audit trailNo customer-visible audit-log capability found in public materialSecurity controls are public, but this row makes no general Trakkr audit-log claimPut required events, retention, search, and export in the order formEvidence: Otterly AI security and terms index, Otterly AI admin, member and viewer roles, Otterly AI SAML single sign-on setup, Otterly AI pricing and plan comparison, Security at TrakkrNot publicly verified. This is a public-documentation finding, not proof that audit records are unavailable in a private Enterprise arrangement. Request scope, retention, export, and event coverage in writing.
Data locationNo selectable residency commitment publicly documentedRegional isolation and certified infrastructure regions are publishedNeither statement alone proves a contractually selectable customer regionEvidence: Otterly AI security and terms index, Otterly AI privacy policy and GDPR information, Otterly AI terms and conditions, Otterly AI pricing and plan comparison, Security at TrakkrNot publicly verified. The company is based in Austria and publishes GDPR material, but that does not establish where customer product data is hosted or whether regional residency can be contracted.
Legal and service termsPublic terms and privacy page; custom Enterprise terms and payment optionsEnterprise lists custom DPAs, legal terms, invoice billing, and SLA guaranteesRequest the complete current package and resolve conflicts in the signed order formEvidence: Otterly AI terms and conditions, Otterly AI privacy policy and GDPR information, Otterly AI pricing and plan comparison, Otterly AI security and terms index, Trakkr plans and Enterprise controlsNot publicly verified. Enterprise contracts may include private service commitments. Buyers should request uptime definitions, exclusions, incident notice, support priority, and service-credit terms.

This page compares public evidence, not private security reports or legal advice. Certification principles are not equivalent to an independent audit certificate.

Is Otterly AI SOC 2 Type II or ISO 27001 certified?

No. Otterly says it operates according to SOC 2 and ISO 27001 principles, but its own help page states that the SOC 2 Type II audit is a roadmap item with no date. It does not claim a current ISO 27001 certificate.

A procurement team should treat this as an explicit gap if vendor-level certification is mandatory, rather than substituting principles or infrastructure controls for an audit report.

Evidence: Otterly AI SOC 2 and ISO 27001 status

How do Otterly AI SSO and roles work?

Enterprise supports SAML 2.0. The customer supplies IdP metadata or its SSO URL, entity ID, and certificate; Otterly then returns service-provider configuration through its authentication system.

Inside the product, Admin controls workspaces, users, and billing; Member manages reports, prompts, and audits; Viewer can read reports and export data. Buyers needing custom roles or SCIM should confirm them separately.

Evidence: Otterly AI SAML single sign-on setup, Otterly AI pricing and plan comparison, Otterly AI admin, member and viewer roles

What remains unclear about audit logs and data residency?

The public security index, SSO guide, roles guide, privacy page, terms page, and Enterprise summary do not document a customer-visible audit trail or a buyer-selectable hosting region.

That is not proof a private Enterprise arrangement cannot supply either. Ask for covered events, actor and IP fields, retention, exports, log integrity, processing locations, subprocessors, transfer safeguards, backup locations, and contractual residency.

Evidence: Otterly AI security and terms index, Otterly AI admin, member and viewer roles, Otterly AI SAML single sign-on setup, Otterly AI pricing and plan comparison, Otterly AI privacy policy and GDPR information, Otterly AI terms and conditionsNot publicly verified. This is a public-documentation finding, not proof that audit records are unavailable in a private Enterprise arrangement. Request scope, retention, export, and event coverage in writing.Not publicly verified. The company is based in Austria and publishes GDPR material, but that does not establish where customer product data is hosted or whether regional residency can be contracted.

What legal and availability material can procurement review publicly?

Is Trakkr stronger than Otterly AI for enterprise security?

Trakkr publishes more technical controls and a broader Enterprise identity set, including SAML or OIDC SSO and SCIM. Otterly publishes a clear SAML setup and three-role permission matrix.

Neither company currently claims its own SOC 2 certification. A buyer with a hard Type II gate should choose neither on public evidence alone; a buyer prioritizing identity breadth and control detail has a stronger Trakkr case.

Evidence: Otterly AI SAML single sign-on setup, Otterly AI pricing and plan comparison, Otterly AI admin, member and viewer roles, Otterly AI SOC 2 and ISO 27001 status, Security at Trakkr, Trakkr plans and Enterprise controls

Evidence and method

Certification status is unusually direct

Otterly explicitly says its Type II audit is future roadmap work without a date, which prevents principles language from being mistaken for certification.

Evidence: Otterly AI SOC 2 and ISO 27001 status

SAML configuration is documented

The official guide names Enterprise entitlement, SAML 2.0, the IdP inputs, service-provider outputs, required email attribute, and managed activation flow.

Evidence: Otterly AI SAML single sign-on setup, Otterly AI pricing and plan comparison

Role permissions are visible

Otterly publishes a concrete Admin, Member, and Viewer matrix across viewing, editing, exporting, audit runs, workspaces, users, and billing.

Evidence: Otterly AI admin, member and viewer roles

Procurement unknowns are bounded

Audit-log, residency, and public availability findings are limited to current first-party material and do not claim that negotiated controls are impossible.

Evidence: Otterly AI security and terms index, Otterly AI admin, member and viewer roles, Otterly AI SAML single sign-on setup, Otterly AI pricing and plan comparison, Otterly AI privacy policy and GDPR information, Otterly AI terms and conditionsNot publicly verified. This is a public-documentation finding, not proof that audit records are unavailable in a private Enterprise arrangement. Request scope, retention, export, and event coverage in writing.Not publicly verified. The company is based in Austria and publishes GDPR material, but that does not establish where customer product data is hosted or whether regional residency can be contracted.Not publicly verified. Enterprise contracts may include private service commitments. Buyers should request uptime definitions, exclusions, incident notice, support priority, and service-credit terms.

How we checked this page

We checked certification, identity, roles, auditability, legal terms, privacy, data location, and availability evidence as separate procurement controls rather than one security score.

  1. 1. Read Otterly AI's current compliance, SSO, role, security-index, terms, privacy, pricing, and Enterprise material.
  2. 2. Recorded missing public evidence as not publicly verified and added the exact contract questions a buyer should resolve.
  3. 3. Compared Trakkr only from current official security and Enterprise documentation checked on the same date.
  • Limitation: We did not receive private audit evidence, penetration-test results, architecture diagrams, a DPA package, or an Enterprise order form.
  • Limitation: This is a public-evidence review and not a certification assessment, penetration test, or legal opinion.

When should enterprise buyers choose Otterly AI or Trakkr?

Choose Otterly AI when Enterprise SAML and its clear three-role model satisfy the control set, and the organization can accept an uncertified vendor while resolving audit, residency, and SLA details contractually.

Choose Trakkr when broader identity support, including OIDC and SCIM, plus a more detailed public technical-control catalog matters. Trakkr also lacks its own SOC 2 today, so neither product fits a procurement policy that requires a vendor Type II report.

Evidence: Otterly AI SAML single sign-on setup, Otterly AI pricing and plan comparison, Otterly AI admin, member and viewer roles, Otterly AI SOC 2 and ISO 27001 status, Otterly AI security and terms index, Otterly AI privacy policy and GDPR information, Otterly AI terms and conditions, Security at Trakkr, Trakkr plans and Enterprise controlsNot publicly verified. This is a public-documentation finding, not proof that audit records are unavailable in a private Enterprise arrangement. Request scope, retention, export, and event coverage in writing.Not publicly verified. The company is based in Austria and publishes GDPR material, but that does not establish where customer product data is hosted or whether regional residency can be contracted.

No. Otterly says the Type II audit is on its roadmap, but it publishes no completion date or current certificate.

See how AI talks about your brand

Enter your domain to get a free AI visibility report in under 60 seconds.

14-day trialCancel anytime60 second setup