Security & Compliance
As of ·
How DATATRONiQ secures the platform, edge gateways, and data customers entrust to us: deployment, tenancy, encryption, identity, updates, compliance status.
Security principles
Industrial data leaves the plant only when the operator chooses. This page describes the technical and organizational measures DATATRONiQ uses to secure the platform, the edge gateways, and the data customers entrust to us. It is written for procurement, information security, data protection officers, and plant-IT leads who need to evaluate a supplier in hours, not days.
Three principles shape every architectural decision:
- 01 Data ownership stays with the customer.
- 02 What the customer does not explicitly release does not leave the customer's infrastructure.
- 03 Every security-relevant action is traceable through audit logs, signed releases, and versioned manifests.
At a glance
The summary below mirrors how the same questions arrive in an InfoSec questionnaire.
- Deployment models
- on-premises · hybrid · air-gapped (Kubernetes or bare metal)
- Tenancy model
- one stack per customer; no shared compute, no shared storage
- Encryption
- mTLS between all components · TLS 1.3 at the perimeter · at-rest encryption configurable per customer
- Identity & access
- OAuth 2.0 · OIDC · SSO federation (SAML/OIDC) · role-based authorization
- Operations & updates
- signed, declarative releases · rollback from a single manifest · GitOps audit trail
- Compliance
- ISO 27001 (implementation underway) · TISAX (implementation underway) · GDPR-compliant
Deployment and tenancy
DATATRONiQ ships in three configurations.
- On-premises
- The entire stack runs in the customer's data center or plant network, with the customer operating clusters and storage.
- Hybrid
- Edge gateways in the plant, control plane and analytics in a customer-owned cloud subscription, jointly operated.
- Air-gapped
- No outbound connectivity; updates arrive as a signed bundle through a controlled gate.
In every configuration, each customer is a separate stack. There is no shared database cluster, no shared object store, no shared model registry across customers. Tenancy is enforced through deployment boundaries, not through tenant IDs. Key ownership depends on the configuration; the handover is part of onboarding and documented in a handover protocol.
Edge security (OT/IT)
The DATATRON gateway runs inside the OT network, terminates there, and speaks to the platform over mTLS. The edge stack is installed on a hardened, in-house-maintained Linux; only the services required for ingest, inference, and uplink are active.
OS and model updates are signed, declarative, and rollback-safe. A plant can run for weeks without internet connectivity; on reconnect, state converges from a single manifest. Writes to PLC or drive systems require an asset-specific policy; without a policy, the gateway stays read-only.
OT/IT separation is not drawn at the platform boundary. It is drawn at the gateway: field-bus interfaces (OPC UA, MQTT, PROFINET, EtherCAT, Modbus) are logically isolated from the uplink side, and the operator controls by policy what telemetry leaves the plant network at all.
Identity, access, and secrets
Users and machines authenticate through OAuth 2.0 and OIDC; federation with the customer's identity provider via SAML or OIDC is the default configuration. Authorizations are role-based; workload credentials are short-lived and centrally rotated.
Internal access to production at DATATRONiQ follows need-to-know, is logged, and is contractually scoped to purpose. Secrets live in a central secrets manager, not in code, not in container images, not in variable files.
Data flow and audit
DATATRONiQ processes machine telemetry, pipeline configuration, and, where the customer configures it, operator identifiers in audit logs. Personal data of plant staff is captured only when the customer explicitly provides for it in the pipeline configuration.
Every connector writes an audit log: who called which endpoint, when, with what payload signature, with what result. Retention windows for telemetry and logs are customer-configurable; the default follows data minimization.
Software supply chain
Releases are cryptographically signed; the edge gateway verifies the signature before applying any update and rejects unsigned or revoked artifacts. A software bill of materials (SBOM) for the platform and the edge stack is available on request.
Build and deploy pipelines are GitOps-managed; every production change is traceable to a single commit. Dependencies and container images are continuously scanned for known vulnerabilities; critical findings carry their own service-level commitment for patch and rollout.
Compliance and legal
DATATRONiQ processes personal data only on behalf of the customer within the meaning of Art. 28 GDPR. A data processing agreement (DPA) is signed before any production use.
ISO 27001 and TISAX: implementation is underway. Scope and auditor will be named on this page once they are fixed. The asterisks on the corresponding spec line elsewhere on the site indicate the same status.
Industry frameworks such as IEC 62443 (industrial cyber security) and NIS2 inform the architecture without DATATRONiQ claiming a separate certification of its own. Operators in scope of NIS2 receive the artifacts they need for their own compliance on request.
Incident response and notification
Security incidents are handled through a documented response process: detect, contain, preserve evidence, recover, learn. The order is not negotiable.
Customers are notified of reportable security incidents without undue delay; the specific window is set in the DPA and aligned with Art. 33 GDPR. The contact for incidents is in the Contact section below.
Reporting vulnerabilities
Security researchers, customers, and partners can report vulnerabilities at any time to security@datatroniq.com. A file at /.well-known/security.txt bundles contact and scope. Coordinated disclosure follows a 90-day default window, shortened by risk.
DATATRONiQ will not pursue legal action against researchers who act in good faith, follow coordinated disclosure, and do not exfiltrate customer or employee data.
Documents on request
The following are made available under NDA or after contract:
- Data Processing Agreement (DPA) under Art. 28 GDPR;
- List of sub-processors for hosted components;
- Software bill of materials (SBOM);
- Excerpts from ISMS policies on access control, incident response, and asset management.
Requests, with subject-line keyword, to security@datatroniq.com or via the contact form.
Contact
- Security
- security@datatroniq.com · vulnerabilities, incidents
- Data protection
- privacy@datatroniq.com
- Address
- DATATRONiQ GmbH · Uhlbacherstraße 75 · 70329 Stuttgart, Germany · info@datatroniq.com