Security and data
What a security review asks, with the limits of each control stated.
Connectivity, off your network
The standard deployment uses a gateway with its own cellular connection, so monitoring need not touch your corporate network — no firewall change, no segment for us. Where coverage is poor, satellite backhaul is available instead.
Which a site uses is decided at deployment. They are alternatives, not a failover pair, and every site needs power and one workable route out.
Access and separation
Sign-in runs through a third-party identity provider. Access is granted per named account and role; you tell us who to add, change or remove. Our own administrative access is limited to named administrators.
Customer records are separated within the application, so one customer’s session does not reach another’s data — application-level separation, not a dedicated database or network per customer.
Where your data lives
Readings and backups are stored in the United States, on hardware we manage rather than shared public cloud. Backups go to a second US provider, encrypted before they leave us, so that provider holds nothing readable.
Supporting services handle limited data on our behalf — sign-in, and delivery of SMS, voice and email alerts. Our agreement also allows aggregated statistics on service performance; a full list is available on request.
What report fingerprints prove
Completed reports carry SHA-256 fingerprints of the readings behind them and of the report record; we keep the matching values. A report is checked by recomputing the fingerprint and comparing it with our copy.
A fingerprint detects change only against that reference. Alone it proves neither authorship, nor that a reading was correct, nor that a file cannot be altered. The printed value covers the data behind the report, so editing the PDF does not change it.
When something fails
The service runs on clustered hosting, so losing a node does not take monitoring down. That covers node failure, not every carrier, power or site failure, and we do not guarantee uninterrupted service.
Supported gateways and sensors buffer readings and retransmit when the link returns, within that device’s configuration and storage limit, which a long outage can exceed. Buffering protects the record, not the alarm: an offline site sends no real-time alerts, though loss of contact is detected on our side and alerts you.
Backups, retention and export
History is backed up off site; we have restored from those backups and verified what came back against what went in.
We retain your history for the life of your service and can produce any date range on request. Export is a full JSON extract of your readings, and live alert and event data can be pushed to your systems by webhook. Retention supports your compliance work; it does not by itself satisfy HACCP or any other program.
Notification, support and procurement
If we determine customer data has been affected, we notify you, then follow up with an assessment of scope and impact.
Automated alerting runs continuously; human support is during business hours. Response targets: same business day for anything affecting monitoring, one business day for sensor, dashboard and alert-configuration issues, two to three for user and threshold changes — targets, not resolution guarantees.
We provide a certificate of insurance and a W-9 and will sign your MSA. Our standard agreement, third-party list and further security detail are available on request.
