Security

Plant LAN never touched. Per-pod keys. Encrypted end to end.

Five pillars that explain how a pod reports on cellular, how its credentials are issued and rotated, what sits underneath the TLS handshake, where your data lives, and what we're working toward for SOC2.

Pod to cellular carrier to Thrumcast cloudThe pod reports on its built-in cellular modem straight to the Thrumcast cloud. Plant LAN, IoT gateway, PLC network, and inbound traffic are all absent from this path.Asset tagPump · motorconveyorPod · LTE-MCellular uplink (outbound only)Thrumcastcloud ingestTLS 1.3 · mTLSAES-256 at restPlant LANVLAN · PLC · IoT gatewayNo inbound — pod listens on nothingOutbound cellular only. No port mapping. No inbound rules. The plant network has nothing to allow, deny, or audit for Thrumcast.

Pillar 1

Data flow. Plant LAN never touched.

The pod reads vibration, current draw, and skin temperature on its built-in LTE-M modem and transmits on cellular. There is nothing on the plant side this traffic touches.

  • No inbound ports — pod listens on nothing.
  • No DNS resolution against the plant resolver.
  • No IoT gateway or PLC traffic.
  • No port mapping, NAT pinholes, or inbound firewall rules needed.

If the corporate network is down for a patch, the pod keeps reporting. Cellular out, not LAN in.

Pillar 2

Per-pod credentials. Rotated every 30 days.

Each pod ships with its own X.509 certificate, minted at the factory and written to a hardware-backed keystore. The dashboard rotates the cert every thirty days, and a revoked cert is rejected at the cloud edge before any payload is parsed.

  • Per-pod — never shared across hardware.
  • Hardware-backed private key; not extractable.
  • Auto-rotated every 30 days via the dashboard.
  • Revoked immediately on loss or decommission.
  • Every rotation logged and auditable for 7 years.
Per-pod rotating credentialsEach pod carries its own X.509 certificate, minted at manufacture. The dashboard rotates it every thirty days. A revoked cert is rejected at the cloud edge before payload parse.Pod #AT-0042Device identityX.509 (provisioned at mfg)SHA-256: 9f2e ··· c8412048-bit RSA · ECDSA P-256 fallbackPer-pod · never sharedmTLS handshakeDashboard rotationDay 15/30Auto-rotates · 30-day cycleRevoked cert → rejected at cloud edge before payload is even parsedEvery rotation logged · auditable for 7 yearsEvery pod has its own cert. None are shared across hardware. A revoked cert is dead on arrival at the ingest endpoint.

Pillar 3

TLS 1.3 in transit. AES-256 at rest.

The handshake is mutually authenticated and pinned at the modem firmware layer. The bucket is envelope-encrypted, the keys are customer-managed, and the bucket, key, and access logs live in three separate IAM roles.

Pillar 3A

In transit

Transport
TLS 1.3 (pod → ingest)
Mutual auth
mTLS; per-pod X.509 verified at edge
Cipher suite
AEAD chacha20-poly1305 / AES-GCM only
Pin
Modem firmware pins the cloud cert chain

Pillar 3B

At rest

Encryption
AES-256 envelope, SSE on ingest bucket
Key custody
Customer-managed keys via cloud KMS
Rotation
Bucket key rolls every 90 days
Separation
Bucket / key / logs sit in distinct IAM roles

Pillar 4

Pick a region at onboarding. The data stays there.

Customer payload lives in the region you choose. Backups live in the same region. The dashboard reads from the same region. There is no cross-region replication for your data — if you don't want it leaving Texas, it doesn't leave Texas.

Primary

United States

Default region for new customers. us-east-1 primary, us-west-2 standby. Standard onboarding SLA.

  • SOC2-bound data processing addendum.
  • Backups in the same region. Same provider.
On request

European Union

Available on request for customers with a documented EU residency requirement. eu-central-1 primary, eu-west-1 standby.

  • GDPR-aligned DPA on file before go-live.
  • No data export outside the region without written request.

Tell us at onboarding which region you want. We sign the DPA, turn the lights on in that region, and never replicate your payload anywhere else.

Pillar 5

SOC2-ready controls. Type 1 by Q4.

The controls a SOC2 auditor expects are in place. Type 1 observation window closes in Q4. Type 2 follows. If your procurement review needs an artifact today, ask and we ship it.

  1. SOC2 Type 1

    Q4 2026
  2. SOC2 Type 2

    Following audit cycle
  3. Annual pen-test report

    Every January
  4. Vendor risk questionnaire

    Self-serve artifact
  5. Business Associate Agreement

    On request
  6. Role-based access review

    Quarterly

Full vendor risk questionnaire and DPA available on request. Email us at the address below with your procurement contact.

Ready when you are

Need the long-form artifact?

Full pen-test report, vendor-risk questionnaire, and the data processing addendum go out same-day on request. Pricing for your tier comes inside one business day.