Otterly AI enterprise security, SSO, SOC 2 and procurement
A procurement-focused review of Otterly AI SAML SSO, roles, SOC 2 and ISO status, audit-log uncertainty, legal terms, data residency, uptime evidence, and Trakkr.
Quick answer
Does Otterly AI meet enterprise security, identity, legal, and procurement requirements?
Otterly AI documents Enterprise SAML 2.0 SSO, three account roles, public privacy material, and downloadable legal terms. It does not currently hold SOC 2 or ISO 27001 certification; its SOC 2 Type II audit has no published date. Customer-visible audit logs, selectable data residency, and a public first-party status history or general uptime SLA are not documented, so regulated buyers need written answers before approval.
Key facts and evidence
- SOC 2 and ISO 27001
- No current Otterly certification; SOC 2 Type II is undated roadmap workEvidence: Otterly AI SOC 2 and ISO 27001 status
- Single sign-on
- SAML 2.0 on EnterpriseEvidence: Otterly AI SAML single sign-on setup, Otterly AI pricing and plan comparison
- Roles
- Admin, Member, and ViewerEvidence: Otterly AI admin, member and viewer roles
- Audit logs
- Customer-visible activity records are not publicly documentedEvidence: Otterly AI security and terms index, Otterly AI admin, member and viewer roles, Otterly AI SAML single sign-on setup, Otterly AI pricing and plan comparisonNot publicly verified. This is a public-documentation finding, not proof that audit records are unavailable in a private Enterprise arrangement. Request scope, retention, export, and event coverage in writing.
- Data residency
- A buyer-selectable hosting region is not publicly documentedEvidence: Otterly AI security and terms index, Otterly AI privacy policy and GDPR information, Otterly AI terms and conditions, Otterly AI pricing and plan comparisonNot publicly verified. The company is based in Austria and publishes GDPR material, but that does not establish where customer product data is hosted or whether regional residency can be contracted.
- Legal package
- April 2026 terms and public privacy material; custom Enterprise terms advertisedEvidence: Otterly AI terms and conditions, Otterly AI privacy policy and GDPR information, Otterly AI pricing and plan comparison
Otterly AI procurement evidence checklist
| Control | Otterly AI public evidence | Trakkr public evidence | Procurement conclusion |
|---|---|---|---|
| Vendor SOC 2 | Not certified; Type II audit is on the roadmap without a date | No Trakkr-owned SOC 2 certification currently claimed | Neither vendor clears a hard company-level SOC 2 requirement todayEvidence: Otterly AI SOC 2 and ISO 27001 status, Security at Trakkr |
| Enterprise identity | SAML 2.0 SSO configured through customer IdP metadata | Enterprise lists SAML or OIDC SSO and SCIM provisioning | Trakkr documents the broader identity set; test exact IdP behavior in either productEvidence: Otterly AI SAML single sign-on setup, Otterly AI pricing and plan comparison, Trakkr plans and Enterprise controls |
| Application roles | Admin, Member, and Viewer with a published permission matrix | Role-based access, MFA, row-level isolation, and secure sessions | Otterly's role model is clear; Trakkr publishes more underlying control detailEvidence: Otterly AI admin, member and viewer roles, Security at Trakkr |
| Audit trail | No customer-visible audit-log capability found in public material | Security controls are public, but this row makes no general Trakkr audit-log claim | Put required events, retention, search, and export in the order formEvidence: Otterly AI security and terms index, Otterly AI admin, member and viewer roles, Otterly AI SAML single sign-on setup, Otterly AI pricing and plan comparison, Security at TrakkrNot publicly verified. This is a public-documentation finding, not proof that audit records are unavailable in a private Enterprise arrangement. Request scope, retention, export, and event coverage in writing. |
| Data location | No selectable residency commitment publicly documented | Regional isolation and certified infrastructure regions are published | Neither statement alone proves a contractually selectable customer regionEvidence: Otterly AI security and terms index, Otterly AI privacy policy and GDPR information, Otterly AI terms and conditions, Otterly AI pricing and plan comparison, Security at TrakkrNot publicly verified. The company is based in Austria and publishes GDPR material, but that does not establish where customer product data is hosted or whether regional residency can be contracted. |
| Legal and service terms | Public terms and privacy page; custom Enterprise terms and payment options | Enterprise lists custom DPAs, legal terms, invoice billing, and SLA guarantees | Request the complete current package and resolve conflicts in the signed order formEvidence: Otterly AI terms and conditions, Otterly AI privacy policy and GDPR information, Otterly AI pricing and plan comparison, Otterly AI security and terms index, Trakkr plans and Enterprise controlsNot publicly verified. Enterprise contracts may include private service commitments. Buyers should request uptime definitions, exclusions, incident notice, support priority, and service-credit terms. |
This page compares public evidence, not private security reports or legal advice. Certification principles are not equivalent to an independent audit certificate.
Is Otterly AI SOC 2 Type II or ISO 27001 certified?
No. Otterly says it operates according to SOC 2 and ISO 27001 principles, but its own help page states that the SOC 2 Type II audit is a roadmap item with no date. It does not claim a current ISO 27001 certificate.
A procurement team should treat this as an explicit gap if vendor-level certification is mandatory, rather than substituting principles or infrastructure controls for an audit report.
How do Otterly AI SSO and roles work?
Enterprise supports SAML 2.0. The customer supplies IdP metadata or its SSO URL, entity ID, and certificate; Otterly then returns service-provider configuration through its authentication system.
Inside the product, Admin controls workspaces, users, and billing; Member manages reports, prompts, and audits; Viewer can read reports and export data. Buyers needing custom roles or SCIM should confirm them separately.
What remains unclear about audit logs and data residency?
The public security index, SSO guide, roles guide, privacy page, terms page, and Enterprise summary do not document a customer-visible audit trail or a buyer-selectable hosting region.
That is not proof a private Enterprise arrangement cannot supply either. Ask for covered events, actor and IP fields, retention, exports, log integrity, processing locations, subprocessors, transfer safeguards, backup locations, and contractual residency.
What legal and availability material can procurement review publicly?
Otterly publishes a terms page labelled April 2026 and a privacy and GDPR page. Its Enterprise plan advertises custom terms and payment options.
A public first-party incident history or generally available uptime SLA was not documented in the official index checked. Procurement should request the current agreement, DPA, subprocessor schedule, security exhibit, support terms, incident notice, SLA definitions, and service credits.
Is Trakkr stronger than Otterly AI for enterprise security?
Trakkr publishes more technical controls and a broader Enterprise identity set, including SAML or OIDC SSO and SCIM. Otterly publishes a clear SAML setup and three-role permission matrix.
Neither company currently claims its own SOC 2 certification. A buyer with a hard Type II gate should choose neither on public evidence alone; a buyer prioritizing identity breadth and control detail has a stronger Trakkr case.
Evidence and method
Certification status is unusually direct
Otterly explicitly says its Type II audit is future roadmap work without a date, which prevents principles language from being mistaken for certification.
Evidence: Otterly AI SOC 2 and ISO 27001 statusSAML configuration is documented
The official guide names Enterprise entitlement, SAML 2.0, the IdP inputs, service-provider outputs, required email attribute, and managed activation flow.
Evidence: Otterly AI SAML single sign-on setup, Otterly AI pricing and plan comparisonRole permissions are visible
Otterly publishes a concrete Admin, Member, and Viewer matrix across viewing, editing, exporting, audit runs, workspaces, users, and billing.
Evidence: Otterly AI admin, member and viewer rolesProcurement unknowns are bounded
Audit-log, residency, and public availability findings are limited to current first-party material and do not claim that negotiated controls are impossible.
Evidence: Otterly AI security and terms index, Otterly AI admin, member and viewer roles, Otterly AI SAML single sign-on setup, Otterly AI pricing and plan comparison, Otterly AI privacy policy and GDPR information, Otterly AI terms and conditionsNot publicly verified. This is a public-documentation finding, not proof that audit records are unavailable in a private Enterprise arrangement. Request scope, retention, export, and event coverage in writing.Not publicly verified. The company is based in Austria and publishes GDPR material, but that does not establish where customer product data is hosted or whether regional residency can be contracted.Not publicly verified. Enterprise contracts may include private service commitments. Buyers should request uptime definitions, exclusions, incident notice, support priority, and service-credit terms.How we checked this page
We checked certification, identity, roles, auditability, legal terms, privacy, data location, and availability evidence as separate procurement controls rather than one security score.
- 1. Read Otterly AI's current compliance, SSO, role, security-index, terms, privacy, pricing, and Enterprise material.
- 2. Recorded missing public evidence as not publicly verified and added the exact contract questions a buyer should resolve.
- 3. Compared Trakkr only from current official security and Enterprise documentation checked on the same date.
- Limitation: We did not receive private audit evidence, penetration-test results, architecture diagrams, a DPA package, or an Enterprise order form.
- Limitation: This is a public-evidence review and not a certification assessment, penetration test, or legal opinion.
When should enterprise buyers choose Otterly AI or Trakkr?
Choose Otterly AI when Enterprise SAML and its clear three-role model satisfy the control set, and the organization can accept an uncertified vendor while resolving audit, residency, and SLA details contractually.
Choose Trakkr when broader identity support, including OIDC and SCIM, plus a more detailed public technical-control catalog matters. Trakkr also lacks its own SOC 2 today, so neither product fits a procurement policy that requires a vendor Type II report.
No. Otterly says the Type II audit is on its roadmap, but it publishes no completion date or current certificate.
Yes. Enterprise customers can configure SAML 2.0 SSO by supplying identity-provider metadata or the required SSO URL, entity ID, and certificate.
Yes. It publishes Admin, Member, and Viewer roles with different rights for reports, prompts, audits, workspaces, team management, and billing.
A buyer-selectable hosting region is not publicly documented. Request processing and backup locations, subprocessors, transfer terms, and residency commitments before purchase.
Sources and related reading
See how AI talks about your brand
Enter your domain to get a free AI visibility report in under 60 seconds.