Security

Industrial IoT security you can verify.

This page lists the security controls in ControlCom Connect: what encrypts the data, how the edge agent reaches the cloud, who can access what, and which capabilities depend on plan tier. Written for the IT and OT security review that clears a platform for evaluation.

SOC 2 Type II · AES-256 at rest · TLS 1.3 in transit
Data protection

Encryption on every plan.

Encryption at rest and edge-to-cloud encryption are included on every plan, from Developer to Custom. There is no tier where telemetry travels or sits in the clear.

At rest

AES-256 encryption at rest

Stored platform data is encrypted with AES-256. Encryption at rest is included on every plan.

In transit

TLS 1.3 in transit

Data moving between the edge agent, the cloud, and your browser is encrypted with TLS 1.3. Edge-to-cloud encryption is included on every plan.

Isolation

Multi-tenant data isolation

Each organization's data is logically separated from every other tenant. Cloud data is stored on AWS infrastructure located in the United States.

Network architecture

Outbound-only at the edge.

SCADA security reviews usually start with one question: what does this open into the OT network? The answer here is nothing.

Edge agent

A Docker container that only dials out.

The edge agent is a Docker container running on hardware at the site. It initiates outbound connections only, so no inbound firewall holes are punched into the OT VLAN. It collects and buffers data locally, and alarm thresholds are evaluated at the edge, so local views and alarms keep working through a WAN outage and sync to the cloud when the link returns.

  • Outbound-only. No inbound ports opened into the OT VLAN.
  • Local buffering. Data is collected and held at the site during an internet drop.
  • Local alarm evaluation. Thresholds fire at the edge even when the WAN is down.
Identity and access

Who gets in, and what they can touch.

MFA and role-based access control are included on every plan. Single sign-on via SAML or OIDC is available on the Custom plan.

MFA

Enforced multi-factor authentication

MFA is enforced on user accounts, in the browser and in the mobile apps. Verification codes are delivered via email or SMS and expire after 15 minutes; trusted device records expire after 30 days.

RBAC

Role-based access control

Administrator, Editor, and View roles scope what each user can see and change. Alarm acknowledgements are recorded with user attribution and a timestamp.

Sessions

Session and credential handling

Sign-ins expire on their own and every session is encrypted. Passwords are never stored in a readable form and cannot be retrieved by anyone at ControlCom, only reset by the account holder.

Audit and assurance

The evidence an auditor asks for.

Independent attestation and a tamper-evident record of who did what, when. Tier availability is stated on each control.

Audit trail

Tamper-evident audit logging

Every user action and alarm event is logged in a tamper-evident audit trail, with time-stamped electronic signatures on acknowledgements. Audit logs are included on the Professional and Custom plans.

SOC 2

SOC 2 Type II report

We hold a SOC 2 Type II report, shared under NDA. Report access is included on the Professional and Custom plans.

Part 11

21 CFR Part 11 controls

Enforced MFA, role-based access control, tamper-evident audit logging, and time-stamped electronic signatures implement the controls 21 CFR Part 11 requires of an electronic record system. Customer-led IQ/OQ/PQ validation packages are supported.

Plan availability

Which controls come with which plan.

Encryption, MFA, RBAC, and the outbound-only edge architecture are universal. Audit logs, the SOC 2 report, and SSO are tied to plan tier.

CapabilityAvailability
Encryption at rest (AES-256)All plans
Edge-to-cloud encryption (TLS 1.3)All plans
Enforced MFAAll plans
Role-based access controlAll plans
Outbound-only edge agentAll plans
Audit logsProfessional and Custom
SOC 2 Type II report (under NDA)Professional and Custom
Single sign-on (SAML or OIDC)Custom

This matches the plan comparison on the pricing page, which is the source of truth for what each tier includes.

Deployment options

Hosted platform, on-site edge.

ControlCom Connect runs as a managed service on Amazon Web Services. The ControlCom Edge Server runs on your hardware, inside your network, and connects outward only.

Where it runs

The site keeps running on hardware you control.

ControlCom Connect is hosted on Amazon Web Services; there is no on-premise or private-cloud build of it. The half you host is the ControlCom Edge Server, a containerized application on a machine beside your equipment. It initiates outbound connections only, and threshold alarms, triggers, and Edge HMI panels keep working locally when the internet link drops. Configuration, users and roles, reports, and multi-site rollups run in the hosted service.

  • ControlCom Connect. Managed service on AWS: configuration authority, users and roles, reports, and rollups across sites.
  • ControlCom Edge Server. Docker, Windows MSI, .deb, .rpm, or macOS pkg on hardware you control; outbound connections only.
  • Local operation. Threshold alarms, Triggers, and Edge HMI panels run at the site; optional local storage buffers unsent readings.
FAQ

Security questions, answered.

The questions IT and OT security reviewers ask when clearing ControlCom Connect for evaluation.

We hold a SOC 2 Type II report, available under NDA. Report access is included on the Professional and Custom plans, as listed in the plan comparison on the pricing page.

Get started

Put it in front of your security team.

Book a 30-minute demo and bring your IT and OT reviewers. We walk through the edge architecture and access model, and share the SOC 2 Type II report under NDA on qualifying plans.