Appearance
Security overview
Use this sequence if you are reviewing Dataplicity for production: controls and assurance first, then how people sign in and what they are allowed to do.
What you need
| You need to | Open |
|---|---|
| Answer a security questionnaire | Security and compliance |
| Understand the trust model on a customer network | Trust on someone else's network |
| See where data is processed | Data residency |
| Design organisation roles | Set up roles |
| Turn on SAML and SCIM | SSO and SCIM |
| Investigate security activity or detections | Security activity and detections |
| Protect a personal login | Multi-factor authentication |
| Issue a server-to-server key | API keys |
Guides
| Guide | Description |
|---|---|
| Security and compliance | Controls, certification status, and how to request security review materials. |
| Trust on someone else's network | Outbound connections, device identity, Linux permissions, threat boundaries, review path, and SSH/VPN fit. |
| Data residency | Data locations, regional processing, data categories, and third parties. |
| Set up roles | Practical OEM and customer-portal role sets, stacking, and scope tags. |
| Permission areas | Every verb, area, and grant behind those roles. |
| SSO and SCIM | Directory users stay read-only, local accounts remain usable, Organisation Admin is the password break-glass. |
| Security activity and detections | Security roles, investigation path, and Sentinel export. |
| Teams | Individual accounts instead of shared passwords. |
| Two-factor authentication | Authenticator-app or WebAuthn on a personal login. |
| API keys | Organisation keys for Gateway API integrations. |
| Firewall requirements | Outbound HTTPS URLs for restricted networks. |
| Securing Wormhole services | Application-level security for exposed web services. |
| Audit trails | Access history for support and security review. |
Security checklist
- Start with the four control boundaries
- Give each team member an individual account and a named role
- Authenticate every application published through Wormhole
- Configure NTP on embedded devices for reliable TLS
- Verify the agent's effective Linux identity on the production image
- Compare supported event coverage and retention with your evidence requirements
- Uninstall the agent when decommissioning a device