Skip to main content

Security and trust, no small print

Trust Center

How we protect your plant data, where our compliance stands, and who to write to if you find a security problem.

Platform security

How we protect your plant data

The same scheme on every installation: per-device identity, encryption in transit and per-plant permissions. No exceptions by customer or by plan.

Isolation per installation

Every plant works with its own instance, its own keys and its own permissions. One installation's data shares neither storage nor credentials with another's.

End-to-end encryption

TLS 1.3 and AES-256 from the gateway to the platform. Data leaves the edge encrypted and travels encrypted the whole way, multi-plant deployments included.

Per-device identity

Every edge authenticates with its own X.509 certificate and mutual authentication: the platform verifies the device and the device verifies the platform. Revoking a certificate withdraws that unit's access.

Access by plant and by person

Permissions are set per installation and per user: each person reaches only the plants and areas that concern them.

Continuity with no data loss

If the connection drops, the edge buffers readings locally and resends them once it is back. The plant keeps operating locally and no measurement is lost.

Data ownership and portability

The data your plant generates is yours. We work on open standards such as MQTT, OPC-UA and Modbus, and you can export your history or ask for its deletion whenever you want.

Compliance

Certifications and standards

We publish the real status of each standard, including what is still in progress. This page is updated as soon as it changes.

In progress

ISO/IEC 27001

The international standard for information security management. wattiot is going through certification: we will publish the certificate and its scope on this page as soon as it is issued.

Compliant

GDPR readiness

We process personal data in line with the General Data Protection Regulation: a defined legal basis, minimisation, bounded retention periods, and rights of access, rectification, erasure and portability.

Privacy policy

Security enquiries

Need our security documentation, a completed vendor questionnaire, or detail on how the edge is deployed inside your network? Write to us and we will reply with the right technical person.

Talk to the team

Reporting a vulnerability

If you have found a security flaw in wattiot, tell us before making it public: write tohello@wattiot.io with the steps to reproduce it and the impact you observed. We confirm receipt and keep you informed until it is resolved. We are grateful for responsible disclosure and take no action against anyone investigating in good faith.

Privacy and personal data

To exercise your rights of access, rectification, erasure or portability, or for any question about the processing of personal data, write to hello@wattiot.io. The full detail is in the privacy policy.