AES-256 encryption at rest
Stored platform data is encrypted with AES-256. Encryption at rest is included on every plan.
Encryption at rest and edge-to-cloud encryption are included on every plan, from Developer to Custom. There is no tier where telemetry travels or sits in the clear.
Stored platform data is encrypted with AES-256. Encryption at rest is included on every plan.
Data moving between the edge agent, the cloud, and your browser is encrypted with TLS 1.3. Edge-to-cloud encryption is included on every plan.
Each organization's data is logically separated from every other tenant. Cloud data is stored on AWS infrastructure located in the United States.
SCADA security reviews usually start with one question: what does this open into the OT network? The answer here is nothing.
The edge agent is a Docker container running on hardware at the site. It initiates outbound connections only, so no inbound firewall holes are punched into the OT VLAN. It collects and buffers data locally, and alarm thresholds are evaluated at the edge, so local views and alarms keep working through a WAN outage and sync to the cloud when the link returns.
MFA and role-based access control are included on every plan. Single sign-on via SAML or OIDC is available on the Custom plan.
MFA is enforced on user accounts, in the browser and in the mobile apps. Verification codes are delivered via email or SMS and expire after 15 minutes; trusted device records expire after 30 days.
Administrator, Editor, and View roles scope what each user can see and change. Alarm acknowledgements are recorded with user attribution and a timestamp.
Sign-ins expire on their own and every session is encrypted. Passwords are never stored in a readable form and cannot be retrieved by anyone at ControlCom, only reset by the account holder.
Independent attestation and a tamper-evident record of who did what, when. Tier availability is stated on each control.
Every user action and alarm event is logged in a tamper-evident audit trail, with time-stamped electronic signatures on acknowledgements. Audit logs are included on the Professional and Custom plans.
We hold a SOC 2 Type II report, shared under NDA. Report access is included on the Professional and Custom plans.
Enforced MFA, role-based access control, tamper-evident audit logging, and time-stamped electronic signatures implement the controls 21 CFR Part 11 requires of an electronic record system. Customer-led IQ/OQ/PQ validation packages are supported.
Encryption, MFA, RBAC, and the outbound-only edge architecture are universal. Audit logs, the SOC 2 report, and SSO are tied to plan tier.
| Capability | Availability |
|---|---|
| Encryption at rest (AES-256) | All plans |
| Edge-to-cloud encryption (TLS 1.3) | All plans |
| Enforced MFA | All plans |
| Role-based access control | All plans |
| Outbound-only edge agent | All plans |
| Audit logs | Professional and Custom |
| SOC 2 Type II report (under NDA) | Professional and Custom |
| Single sign-on (SAML or OIDC) | Custom |
This matches the plan comparison on the pricing page, which is the source of truth for what each tier includes.
ControlCom Connect runs as a managed service on Amazon Web Services. The ControlCom Edge Server runs on your hardware, inside your network, and connects outward only.
ControlCom Connect is hosted on Amazon Web Services; there is no on-premise or private-cloud build of it. The half you host is the ControlCom Edge Server, a containerized application on a machine beside your equipment. It initiates outbound connections only, and threshold alarms, triggers, and Edge HMI panels keep working locally when the internet link drops. Configuration, users and roles, reports, and multi-site rollups run in the hosted service.
The questions IT and OT security reviewers ask when clearing ControlCom Connect for evaluation.
We hold a SOC 2 Type II report, available under NDA. Report access is included on the Professional and Custom plans, as listed in the plan comparison on the pricing page.
The pages a security review usually reads next.
The full plan comparison, including which tier carries audit logs, SSO, and the SOC 2 report.
Dashboards, asset management, and analytics on one vendor-neutral industrial IoT platform.
How mission-critical operators run ControlCom Connect alongside DCIM, BMS, and the OT network.
Book a 30-minute demo and bring your IT and OT reviewers. We walk through the edge architecture and access model, and share the SOC 2 Type II report under NDA on qualifying plans.