Security
Plant LAN never touched. Per-pod keys. Encrypted end to end.
Five pillars that explain how a pod reports on cellular, how its credentials are issued and rotated, what sits underneath the TLS handshake, where your data lives, and what we're working toward for SOC2.
Pillar 1
Data flow. Plant LAN never touched.
The pod reads vibration, current draw, and skin temperature on its built-in LTE-M modem and transmits on cellular. There is nothing on the plant side this traffic touches.
- ✕No inbound ports — pod listens on nothing.
- ✕No DNS resolution against the plant resolver.
- ✕No IoT gateway or PLC traffic.
- ✕No port mapping, NAT pinholes, or inbound firewall rules needed.
If the corporate network is down for a patch, the pod keeps reporting. Cellular out, not LAN in.
Pillar 2
Per-pod credentials. Rotated every 30 days.
Each pod ships with its own X.509 certificate, minted at the factory and written to a hardware-backed keystore. The dashboard rotates the cert every thirty days, and a revoked cert is rejected at the cloud edge before any payload is parsed.
- ●Per-pod — never shared across hardware.
- ●Hardware-backed private key; not extractable.
- ●Auto-rotated every 30 days via the dashboard.
- ●Revoked immediately on loss or decommission.
- ●Every rotation logged and auditable for 7 years.
Pillar 3
TLS 1.3 in transit. AES-256 at rest.
The handshake is mutually authenticated and pinned at the modem firmware layer. The bucket is envelope-encrypted, the keys are customer-managed, and the bucket, key, and access logs live in three separate IAM roles.
Pillar 3A
In transit
- Transport
- TLS 1.3 (pod → ingest)
- Mutual auth
- mTLS; per-pod X.509 verified at edge
- Cipher suite
- AEAD chacha20-poly1305 / AES-GCM only
- Pin
- Modem firmware pins the cloud cert chain
Pillar 3B
At rest
- Encryption
- AES-256 envelope, SSE on ingest bucket
- Key custody
- Customer-managed keys via cloud KMS
- Rotation
- Bucket key rolls every 90 days
- Separation
- Bucket / key / logs sit in distinct IAM roles
Pillar 4
Pick a region at onboarding. The data stays there.
Customer payload lives in the region you choose. Backups live in the same region. The dashboard reads from the same region. There is no cross-region replication for your data — if you don't want it leaving Texas, it doesn't leave Texas.
United States
Default region for new customers. us-east-1 primary, us-west-2 standby. Standard onboarding SLA.
- SOC2-bound data processing addendum.
- Backups in the same region. Same provider.
European Union
Available on request for customers with a documented EU residency requirement. eu-central-1 primary, eu-west-1 standby.
- GDPR-aligned DPA on file before go-live.
- No data export outside the region without written request.
Tell us at onboarding which region you want. We sign the DPA, turn the lights on in that region, and never replicate your payload anywhere else.
Pillar 5
SOC2-ready controls. Type 1 by Q4.
The controls a SOC2 auditor expects are in place. Type 1 observation window closes in Q4. Type 2 follows. If your procurement review needs an artifact today, ask and we ship it.
SOC2 Type 1
Q4 2026SOC2 Type 2
Following audit cycleAnnual pen-test report
Every JanuaryVendor risk questionnaire
Self-serve artifactBusiness Associate Agreement
On requestRole-based access review
Quarterly
Full vendor risk questionnaire and DPA available on request. Email us at the address below with your procurement contact.
Ready when you are
Need the long-form artifact?
Full pen-test report, vendor-risk questionnaire, and the data processing addendum go out same-day on request. Pricing for your tier comes inside one business day.