Skip to content

Security overview

Use this sequence if you are reviewing Dataplicity for production: controls and assurance first, then how people sign in and what they are allowed to do.

What you need

You need toOpen
Answer a security questionnaireSecurity and compliance
Understand the trust model on a customer networkTrust on someone else's network
See where data is processedData residency
Design organisation rolesSet up roles
Turn on SAML and SCIMSSO and SCIM
Investigate security activity or detectionsSecurity activity and detections
Protect a personal loginMulti-factor authentication
Issue a server-to-server keyAPI keys

Guides

GuideDescription
Security and complianceControls, certification status, and how to request security review materials.
Trust on someone else's networkOutbound connections, device identity, Linux permissions, threat boundaries, review path, and SSH/VPN fit.
Data residencyData locations, regional processing, data categories, and third parties.
Set up rolesPractical OEM and customer-portal role sets, stacking, and scope tags.
Permission areasEvery verb, area, and grant behind those roles.
SSO and SCIMDirectory users stay read-only, local accounts remain usable, Organisation Admin is the password break-glass.
Security activity and detectionsSecurity roles, investigation path, and Sentinel export.
TeamsIndividual accounts instead of shared passwords.
Two-factor authenticationAuthenticator-app or WebAuthn on a personal login.
API keysOrganisation keys for Gateway API integrations.
Firewall requirementsOutbound HTTPS URLs for restricted networks.
Securing Wormhole servicesApplication-level security for exposed web services.
Audit trailsAccess history for support and security review.

Security checklist

  • Start with the four control boundaries
  • Give each team member an individual account and a named role
  • Authenticate every application published through Wormhole
  • Configure NTP on embedded devices for reliable TLS
  • Verify the agent's effective Linux identity on the production image
  • Compare supported event coverage and retention with your evidence requirements
  • Uninstall the agent when decommissioning a device