Otium One
Not an afterthought

Your leave data isn't just personal. Some of it's sensitive.

Sickness and family leave carry a weight most leave management doesn't account for. Otium One treats them that way from the ground up.

Tenant isolation

Your data is isolated three ways: explicit scoping in every query, an application-level guard as a second line, and row-level security enforced at the database itself. Even if application code contains a bug, database-level row security provides a final barrier against one customer accessing another customer's data.

Authentication

Cookie-based sessions, optional or admin-required multi-factor authentication (TOTP), and breached-password checking on every password set. Repeated failed logins trigger exponential backoff. Deactivating a user ends every session of theirs within a minute, not just at cookie expiry.

Single sign-on

Microsoft Entra ID (formerly Azure AD), connected by your own administrator in one click through Microsoft's standard admin-consent screen — no tenant IDs to look up or send to support. Accounts can be created automatically on first sign-in, guest and personal Microsoft accounts are refused, and Microsoft security groups can map straight to your roles. SCIM 2.0 handles automated user lifecycle management from your identity provider.

Audit & retention

An append-only audit log records every meaningful change — leave requests, approvals, entitlement changes and account changes — with exactly what changed, before and after. Records are kept for six years by default, matching the time limit for most legal claims, and database controls prevent them from being edited or deleted before that window ends.

Data protection

Sickness and family leave are treated as sensitive by default: they're excluded from external notifications and restricted in reporting to authorised administrators. GDPR-aligned erasure is built in for individual users, and full offboarding exports your data before removing it.

Payments

Every payment is handled securely by Stripe, our payment processor — your card details are entered directly on Stripe's own page and never touch our servers, in either direction. We store no card numbers, and updating your card or downloading a receipt happens through Stripe's own billing portal, not ours.

Support access

If our support team ever needs to look at your account to help you, that access is time-boxed, scoped to what's needed, and logged in full — never a standing, silent back door into your data.

Reporting a vulnerability

Found something that doesn't look right? We'd rather hear about it. Email hello@otiumone.co.uk with what you found, the steps to reproduce it, and what an attacker could do with it.

We'll acknowledge your report within three working days, keep you updated while we fix it, and credit you once it's resolved if you'd like us to.

Test only against a free trial account you've set up yourself. Don't access, change or keep anyone else's data, don't degrade the service for other customers, and give us a reasonable chance to fix the issue before you tell anyone else. Research done in good faith within these rules is welcome, and we won't pursue legal action over it.