Security, tenancy and governance
Written for the person who has to sign off on it.
We would rather tell you which controls are running than show you a wall of badges.
Live today
- Encryption in transit
- Traffic between the receiver, the platform and the browser is encrypted with TLS.
- Outbound-only receiver
- The receiver opens a connection out. No inbound firewall rules, no port forwarding, and no VPN to terminate.
- OT network isolation
- The receiver never needs to reach a PLC or a historian to function.
- On-premise deployment
- Available where residency or policy requires the platform to run inside your network.
- Privacy
- Personal information submitted on this site is handled as described in the privacy policy, in line with PIPEDA and GDPR principles.
- Formal certification
- We do not hold SOC 2 or ISO 27001 and we will not claim either. We will complete your security questionnaire, walk your team through the architecture, and share our audit roadmap during procurement.
Committed before general availability
- Tenant isolation
- Every query scoped to the authenticated tenant at the data-access layer.
- Identity
- Enterprise single sign-on with multi-factor authentication and organisation-managed provisioning.
- Role-based access
- Four roles — Operator, Technician, Reliability Engineer, Organisation Admin — enforced at the API.
- Audited support access
- An immutable log entry and a persistent in-session banner on every impersonation.
- Encryption at rest
- Stored data encrypted by the database platform.
These are commitments, not marketing. Ask us where each one stands and we will tell you.