Every user is given a role — operator, supervisor, administrator or ERP — and sees only their own sites and organisations. Critical commands require the matching rights, and every action leaves a trace.
Every action is recorded — who, when and from which session. Alarm history, event stream and export whenever an internal review is needed.
The system monitors its own health and notifies you when something is wrong. Scheduled backups and clear maintenance procedures — no surprises.
Two-factor authentication (TOTP), session management with automatic sign-out on inactivity, and rights by role, site and organisation.
Encrypted communication (TLS/SSL) throughout — web, MQTT and the links to the site loggers. Passwords are stored only as hashes, and API access is protected.
A full history of actions — commands to the units, configuration changes, schedules and system events, each with an exact timestamp and user session.
Real-time attack detection (SQLi, path traversal, scanning), automatic blocking of IP addresses and brute-force protection on sign-in.
The system is watched in real time — on an anomaly or suspicious activity it sends a notification and responds automatically, before the problem grows.
Automatic scheduled backups, a tested disaster recovery plan and clear policies on how long data is kept.
Hosting in a secured cloud environment — automatic updates, scaling when needed and minimal infrastructure work on your side.
Installation on your own infrastructure — full control, isolation and compliance with your internal policies.
Critical data stays local while analytics and reports go to the cloud — a combination that follows your requirements.