中文

Security

Nothing is trusted by default

TrustIoT.AI is built on zero trust. No user, device or network is trusted by default; every access is authenticated and authorised, permissions are granted at the minimum a task needs, and critical operations leave an audit trail.

  • Verify every access
  • Grant the least privilege
  • Record every critical step
  • Keep every customer apart

Architecture

Four layers that are each checked

  1. Edge

    The official gateway

    • TPM 2.0 hardware identity
    • Firmware integrity measured at boot
    • Only registered, verified gateways connect
    • Offline buffering and automatic resend
  2. Transport

    Gateway to cloud

    • Encrypted channels only
    • Mutual certificate authentication
    • Certificates expire and can be revoked
    • Connections that fail are rejected
  3. Cloud

    Hosted on AWS

    • Data encrypted at rest
    • Raw, cleaned and analytical data kept apart
    • Each customer's readings in a database of their own
    • Audit logs stored apart from business data
  4. AI

    Model requests

    • Only the minimum necessary content reaches a model
    • Every model request passes one governed gateway
    • Queries locked to your own data
    • Answers kept within the authorised scope

Access

People and roles on record

  • Named accounts

    No shared accounts; every operation is recorded under a person's name.

  • Separate roles

    Administrators, operators and viewers are authorised separately.

  • One-time sign-in codes

    Sign-in uses a one-time code sent to your work email.

  • No direct database access

    Nobody queries or changes production databases by hand.

Your data

Your data stays yours

  • You keep full ownership of your data
  • It is never used to train public or shared models
  • It is not given to third parties without your authorisation
  • Export and deletion follow your agreement
Future Generation Computer Systems

Research

Built on published research

The zero-trust design of the gateway comes from Laysi Research on edge nodes, published in Future Generation Computer Systems, an international journal from Elsevier.

Zero-trust node security for KubeEdge: A policy-as-service architecture and reliability evaluation

A compromised edge node can go on appearing healthy. The work has each node continually prove its trustworthiness with hardware-rooted evidence, and isolate itself on site when verification fails or the cloud falls out of reach. Its reliability is evaluated across 900 automated runs.

Read the paper About Laysi

Put your first gateway on the line

Tell us about your equipment and what you would like to solve first. We will shape a rollout plan around your site and work through it with you from the first step.

Get a rollout plan