Trust & Security

Security is the baseline, not a feature we sell separately

Here's exactly how SingleIoT protects device data, account access and the infrastructure that runs on top of it.

Encryption everywhere

TLS 1.3 in transit and AES‑256 at rest, with per‑device credentials that rotate automatically — no shared secrets across your fleet.

Strict access control

Role‑based permissions, SSO/SCIM for Enterprise, and every administrative action recorded in an immutable audit log.

Continuous monitoring

Automated anomaly detection across our infrastructure, with an on‑call team ready to respond to incidents around the clock.

Data residency & isolation

Your telemetry is logically isolated from every other account by default. Enterprise customers can additionally request a dedicated regional deployment to meet data residency requirements.

  • Per‑account data isolation by default
  • Regional hosting available for Enterprise
  • Full data export or deletion on request

Incident response

We run a documented incident response process with defined severity levels. Enterprise customers with an SLA are notified proactively, before they'd need to ask.

  • Defined severity levels and response targets
  • Proactive status updates during incidents
  • Post‑incident reports for Enterprise accounts

Our security program

SingleIoT's security practices are modeled on widely recognized frameworks for information security and cloud data handling. We undergo regular independent security assessments and penetration testing, and Enterprise customers can request our current security documentation and assessment summaries as part of their vendor review process.

Sub‑processors

We rely on a small number of vetted infrastructure providers for hosting, email delivery and error monitoring — never more than necessary to run the service. Each is bound by a data processing agreement, and a current list is available on request.

Responsible disclosure

If you believe you've found a security vulnerability in SingleIoT, we want to hear about it. Please report it through our contact page with the subject "Security disclosure" — we aim to acknowledge reports within one business day and do not pursue legal action against good‑faith research.

Shared responsibility

We secure the platform, infrastructure and data pipeline. You're responsible for keeping account credentials safe, configuring role permissions appropriately, and physically securing devices in the field. Our onboarding team can help you set this up correctly from day one.

Need a security review for procurement?

Request our latest security documentation, architecture overview or a call with our team.