Security
Nothing is trusted by default
TrustIoT.AI is built on zero trust. No user, device or network is trusted by default; every access is authenticated and authorised, permissions are granted at the minimum a task needs, and critical operations leave an audit trail.
- Verify every access
- Grant the least privilege
- Record every critical step
- Keep every customer apart
Architecture
Four layers that are each checked
Edge
The official gateway
- TPM 2.0 hardware identity
- Firmware integrity measured at boot
- Only registered, verified gateways connect
- Offline buffering and automatic resend
Transport
Gateway to cloud
- Encrypted channels only
- Mutual certificate authentication
- Certificates expire and can be revoked
- Connections that fail are rejected
Cloud
Hosted on AWS
- Data encrypted at rest
- Raw, cleaned and analytical data kept apart
- Each customer's readings in a database of their own
- Audit logs stored apart from business data
AI
Model requests
- Only the minimum necessary content reaches a model
- Every model request passes one governed gateway
- Queries locked to your own data
- Answers kept within the authorised scope
Access
People and roles on record
Named accounts
No shared accounts; every operation is recorded under a person's name.
Separate roles
Administrators, operators and viewers are authorised separately.
One-time sign-in codes
Sign-in uses a one-time code sent to your work email.
No direct database access
Nobody queries or changes production databases by hand.
Your data
Your data stays yours
- You keep full ownership of your data
- It is never used to train public or shared models
- It is not given to third parties without your authorisation
- Export and deletion follow your agreement

Research
Built on published research
The zero-trust design of the gateway comes from Laysi Research on edge nodes, published in Future Generation Computer Systems, an international journal from Elsevier.
Zero-trust node security for KubeEdge: A policy-as-service architecture and reliability evaluation
A compromised edge node can go on appearing healthy. The work has each node continually prove its trustworthiness with hardware-rooted evidence, and isolate itself on site when verification fails or the cloud falls out of reach. Its reliability is evaluated across 900 automated runs.
Put your first gateway on the line
Tell us about your equipment and what you would like to solve first. We will shape a rollout plan around your site and work through it with you from the first step.
Get a rollout plan