Skip to content

Security overview

Use this sequence to review Dataplicity's controls, deployment assumptions, current assurance posture, and production configuration.

GuideDescription
Security and complianceControls, certification status, and how to request security review materials.
Trust on someone else's networkOutbound connections, device identity, Linux permissions, threat boundaries, review path, and SSH/VPN fit.
Data residencyData locations, regional processing, data categories, and third parties.
Two-factor authenticationAdd authenticator-app or WebAuthn protection to your account login.
TeamsShare device access without sharing passwords.
Firewall requirementsOutbound HTTPS URLs for restricted networks.
Securing Wormhole servicesApplication-level security for exposed web services.
Audit trailsAccess history for support and security review.

Security checklist

  • Start with the four control boundaries
  • Give each team member an individual account and role
  • Authenticate every application published through Wormhole
  • Configure NTP on embedded devices for reliable TLS
  • Verify the agent's effective Linux identity on the production image
  • Compare supported event coverage and retention with your evidence requirements
  • Uninstall the agent when decommissioning a device