SECURITY_ARCHITECTURE_V2

Your data doesn't leave your plant.
Unless you order it to.

Designed for hostile environments and paranoid auditors. iGromi OS implements a Zero-Trust architecture from the sensor to the cloud.

LEVEL 0-1

OT Network (Plant)

PLCs, Sensors, Local SCADA.
NO INTERNET ACCESS

iGromi Edge Gateway
LEVEL 4-5

Cloud / IT

Remote Dashboard, ERP, Alerts.
ENCRYPTED DATA ONLY

Network Invisibility (Stealth Mode)

iGromi OS does not open inbound ports. All traffic is outbound. This means your plant is invisible to scanners like Shodan or attack bots. You cannot attack what you cannot see.

WireGuard® Tunnels

We use WireGuard, the most modern and lightweight VPN protocol, to establish point-to-point encrypted tunnels. It works even behind 4G cellular networks with strict CGNAT, without needing fixed public IPs.

Data Sovereignty (Local-First)

Your historical data is stored first on the Edge device's SSD (configurable Retention Policy). If you decide to cut the internet, the system keeps operating and storing data locally for years.

Container Isolation

Each application (Node-RED, Database, AI) runs in its own isolated Docker container. If a process fails or is compromised, it does not affect the rest of the OS or the control network.

Need to validate this with your IT/Cybersecurity team?

Download our technical security architecture whitepaper to present to your CISO.

Read Security Whitepaper