Encrypted in Transit
Connections between gateways, servers, browsers and brokers use TLS. MQTT runs over TLS with credentials or client certificates.
Most industrial protocols predate today's threats. IoTServa adds the controls they lack and tells you where the gaps are.

Connections between gateways, servers, browsers and brokers use TLS. MQTT runs over TLS with credentials or client certificates.
Users get roles, and roles are scoped to the sites and buildings they need. An operator for one site does not see another.
A site can be set to read-only. Writing to a device is a separate permission, switched on deliberately and logged.
Changes to configuration and every write to a device are recorded with who, what and when.
Broker passwords, API keys and certificates are stored as secrets, not inside project exports or shared profiles.
A gateway initiates its connection outward, so you do not have to open inbound ports to the equipment network.
These are properties of the protocols, not of IoTServa. Plan the network around them.
Modbus. Has no built-in authentication or encryption. Anyone on the network segment can read or write registers.
BACnet/IP. Classic BACnet/IP is unauthenticated. BACnet/SC adds secure connections where devices support it.
KNX IP. Unsecured by default. KNX Secure adds encryption and authentication where the installation supports it.
LoRaWAN. Encrypts payloads end to end with session keys. Keys must be provisioned and stored carefully.
No certification is claimed on this site. Ask us about the controls you require and we will answer against your checklist.
No. Keep equipment networks segmented, and let a gateway connect outward to IoTServa instead of exposing devices.
We will answer each control honestly, including the ones that depend on your network design.