Appearance
Security and compliance
Dataplicity uses layered technical and operational controls to protect customer accounts, fleet data, and remote access.
Certification status
Dataplicity is not currently ISO 27001 certified and has not completed a SOC 2 attestation. Use the control descriptions below for your security assessment, and contact Dataplicity if you need current certification status or other assurances confirmed in writing.
Security controls
The following controls are in place:
- Authentication and access: individual accounts, role and tenant checks, multi-factor authentication, and SSO or SCIM where enabled for the organisation
- Least privilege: scoped application roles, organisation and network filtering, and an unprivileged default device-agent identity
- Encryption: TLS for public service connections; encryption at rest for production databases, object storage, and backups
- Tenant separation: organisation, network, device, and object-level authorisation checks
- Audit and monitoring: product audit records for supported actions, and centralized service logging
- Change management: source-controlled infrastructure and application changes, with automated tests and security checks before production deployment
- Backups and recovery: automated database backups with encrypted storage
- Incident handling: a documented process for detection, containment, assessment, notification, remediation, and follow-up
- Device-side boundary: terminal, file, fleet, and confirmed AI-assisted command paths inherit the permissions granted to the configured device OS identity
These descriptions summarise how Dataplicity is built and operated. They are not a warranty that every risk is eliminated. Availability of SSO, SCIM, audit surfaces, or other features can depend on organisation configuration and current entitlements.
See the security model for architecture details, including the outbound connection model and device-side privilege boundary.
Security reviews and agreements
For a security questionnaire, architecture discussion, data processing agreement, or current subprocessor information, contact support@dataplicity.com.
If your organisation requires contractual commitments such as certification, independent assessment access, recovery objectives, or uptime or incident-response SLAs, confirm those terms in a signed agreement. See Data residency for current deployment locations and regional considerations. Single-region-only processing is not currently available.