AES-256 encryption at rest
Stored platform data is encrypted with AES-256. Encryption at rest is included on every plan.
Encryption at rest and edge-to-cloud encryption are included on every plan, from Developer to Enterprise. There is no tier where telemetry travels or sits in the clear.
Stored platform data is encrypted with AES-256. Encryption at rest is included on every plan.
Data moving between the edge agent, the cloud, and your browser is encrypted with TLS 1.3. Edge-to-cloud encryption is included on every plan.
Each organization's data is logically separated from every other tenant. Cloud data is stored on AWS infrastructure located in the United States.
SCADA security reviews usually start with one question: what does this open into the OT network? The answer here is nothing.
The edge agent is a Docker container running on hardware at the site. It initiates outbound connections only, so no inbound firewall holes are punched into the OT VLAN. It collects and buffers data locally, and alarm thresholds are evaluated at the edge, so local views and alarms keep working through a WAN outage and sync to the cloud when the link returns.
MFA and role-based access control are included on every plan. Single sign-on via SAML or OIDC is included on the Enterprise plan.
MFA is enforced on user accounts, in the browser and in the mobile apps. Verification codes are delivered via email or SMS and expire after 15 minutes; trusted device records expire after 30 days.
Administrator, Editor, and View roles scope what each user can see and change. Alarm acknowledgements are recorded with user attribution and a timestamp.
Sign-ins expire on their own and every session is encrypted. Passwords are never stored in a readable form and cannot be retrieved by anyone at ControlCom, only reset by the account holder.
Independent attestation and a tamper-evident record of who did what, when. Tier availability is stated on each control.
Every user action and alarm event is logged in a tamper-evident audit trail, with time-stamped electronic signatures on acknowledgements. Audit logs are included on the Professional and Enterprise plans.
We hold a SOC 2 Type II report, shared under NDA. Report access is included on the Professional and Enterprise plans.
Enforced MFA, role-based access control, tamper-evident audit logging, and time-stamped electronic signatures implement the controls 21 CFR Part 11 requires of an electronic record system. Customer-led IQ/OQ/PQ validation packages are supported.
Encryption, MFA, RBAC, and the outbound-only edge architecture are universal. Audit logs, the SOC 2 report, and single sign-on are tied to plan tier.
| Capability | Availability |
|---|---|
| Encryption at rest (AES-256) | All plans |
| Edge-to-cloud encryption (TLS 1.3) | All plans |
| Enforced MFA | All plans |
| Role-based access control | All plans |
| Outbound-only edge agent | All plans |
| Audit logs | Professional and Enterprise |
| SOC 2 Type II report (under NDA) | Professional and Enterprise |
| Single sign-on (SAML or OIDC) | Enterprise |
This matches the plan comparison on the pricing page, which is the source of truth for what each tier includes.
ControlCom Connect runs as a managed service on Amazon Web Services. The ControlCom Edge Server runs on your hardware, inside your network, and connects outward only.
ControlCom Connect is hosted on Amazon Web Services; there is no on-premise or private-cloud build of it. The half you host is the ControlCom Edge Server, a containerized application on a machine beside your equipment. It initiates outbound connections only, and threshold alarms, triggers, and Edge HMI panels keep working locally when the internet link drops. Configuration, users and roles, reports, and multi-site rollups run in the hosted service.
The questions IT and OT security reviewers ask when clearing ControlCom Connect for evaluation.
We hold a SOC 2 Type II report, which means an independent auditor examined our security controls operating over a period of time, not just their design on paper. The report is shared under NDA, which is standard practice for SOC 2, since the document describes the control environment in detail. Report access is included on the Professional and Enterprise plans, as listed in the plan comparison on the pricing page and in the plan availability table on this page. For a security review, the practical sequence is: use this page to confirm the platform covers your baseline requirements (encryption at rest and in transit, enforced MFA, role-based access control, and the outbound-only edge architecture), then request the report through your account contact once an NDA is in place, and give your auditors the full control detail. The controls described on this page, including session and credential handling, are covered by the report.
The pages a security review usually reads next.
The full plan comparison, including which tier carries audit logs and the SOC 2 report.
Dashboards, asset management, and analytics on one vendor-neutral industrial IoT platform.
How mission-critical operators run ControlCom Connect alongside DCIM, BMS, and the OT network.
Book a 30-minute demo and bring your IT and OT reviewers. We walk through the edge architecture and access model, and share the SOC 2 Type II report under NDA on qualifying plans.
Sizing it up?See plans and allotments.