Security and data protection

Telemetry2U Data Security Policy

This policy outlines the technical and administrative safeguards used to protect platform data, customer information and access to connected monitoring systems.

Authentication and Password Security

Access to Telemetry2U is protected through password hashing, account verification and supported external authentication providers.

Password Management

Passwords are never stored in plaintext. They are hashed using HMAC-SHA512 with a 128-bit salt, a 256-bit subkey and 100,000 iterations.

The password policy requires at least one uppercase character, one lowercase character, one digit and one non-alphanumeric character, with a minimum length of six characters. Password reset requests require verification through email.

External Authentication

Authentication through external OAuth 2.0 providers is supported where configured. Users signing in through a supported provider do not disclose their external account password to Telemetry2U.

Data Encryption and Secure Hosting

Customer information is protected while stored locally, replicated to cloud infrastructure and transferred between systems.

Data Encryption at Rest

Customer textual data is encrypted at rest using AES-256 encryption through a locally installed FIPS-certified encryption provider. This includes company names, contact names, telephone numbers, dashboard names and sensor names.

Data Replication and Cloud Hosting

Data is replicated hourly to a cloud provider. Transfers are protected using TLS encryption, and the replicated database remains encrypted at rest.

The current cloud provider is Microsoft Azure, using the South East Australia region. Review the Microsoft Azure privacy information.

Alert Delivery Security

Alert messages use encrypted transport where supported, while message content is limited to the information required to identify and respond to an event.

SMS and Voice Alerts

When an alert is delivered by SMS or voice call, the message is transferred using TLS to the messaging provider. The provider receives the unencrypted message content required to deliver the alert.

The current provider is Twilio Inc. Alert content is limited to the recipient number, sensor name and current reading or sensor state. Review the Twilio Privacy Notice.

Email Alerts

Email alerts are sent from an internal email server using SMTP over TLS when the receiving server supports it, without using a third-party email delivery service. Depending on the recipient's email configuration, a message may pass through multiple mail servers with or without encryption.

Email alert content is limited to the recipient's email address, sensor name and current reading or sensor state.

Application and Transport Security

The web platform uses modern framework protections, encrypted connections and regularly maintained server infrastructure.

Web Application Security

Telemetry2U uses a modern development framework with protections designed to reduce exposure to common threats such as SQL injection and cross-site scripting (XSS). Pages also define a Content Security Policy (CSP) to further reduce the risk of web-based attacks.

Transport Security

HTTP Strict Transport Security (HSTS) is enforced so browser connections use TLS over HTTPS.

System and Server Updates

Server and networking-device operating systems are regularly updated to apply current security patches.

Firewall and Threat Protection

Layered firewall controls restrict direct access to internal services and help detect suspicious activity before it reaches protected systems.

Firewall Configuration

Servers use operating-system-level firewalls to restrict access to sensitive resources, including database and network services, to internal systems that require them.

A hardware firewall prevents direct external access to database and network servers. Only the minimum required incoming ports are allowed, including HTTPS and the transport ports needed for supported device protocols such as LoRaWAN, NB-IoT and LTE-M.

Data received through these ports is validated and authenticated before it is accepted. The receiving software is developed using languages and frameworks designed to reduce exposure to buffer-overflow and related attacks.

Threat Detection and Intrusion Prevention

The hardware firewall is configured to detect and block threats such as port scanning and flooding attacks.

An active threat-detection system monitors for penetration attempts, including SQL injection and unauthorised port access. When an attempt is detected, the source IP address is automatically blocked through the hardware firewall. Events are logged and reported so further action, such as blocking an IP address range, can be taken where necessary.

User-Level Security and Access Control

Administrators control which platform functions and monitoring nodes each user can access. New users receive no operational access until permissions are explicitly assigned.

User Roles and Permissions

Administrators can assign specific roles that provide access to different platform features. Available roles include Actions Admin, Add Annotations, Alert Admin and other task-specific roles.

For example, the Actions Admin role allows a user to create downlink command lists that can be triggered by sensor events or schedules. This role-based approach limits users to the functions required for their responsibilities.

Node Access Control

Users can only be granted access to nodes already available under the administrator's account. Node access must be assigned by an authorised administrator, limiting device visibility and control to approved users.

Default Access Restrictions

A newly invited user is not given access to nodes or platform functions by default. Administrators must explicitly assign the required roles, permissions and node access before that user can interact with monitoring data or controls.

User Responsibilities

Users are responsible for protecting their login credentials and must not share their account. Suspicious activity should be reported to the account administrator or Telemetry2U support. Users must also comply with the platform's acceptable-use requirements.

Audit Logging and Compliance

Additional audit controls are available for accounts that require regulated electronic records and traceable user activity.

Audit Logging

When 21 CFR Part 11 controls are enabled, Telemetry2U maintains detailed audit records for user actions, including sign-ins, configuration changes and administrative events.

Authorised administrators can review and download these records to support compliance checks and investigate potential misuse or unauthorised activity.

Security Questions

Contact Telemetry2U if you need more information about this policy or the safeguards applied to your platform data.

Use the contact page to send a data-security or compliance question to our team.