---
title: "wattiot | Trust Center: security and compliance"
description: "How wattiot protects your plant data: isolation per installation, TLS 1.3, X.509 certificates and per-plant permissions. Status of ISO/IEC 27001 and GDPR."
source: "https://wattiot.io/en/trust-center/"
language: "en"
---

# Security and trust, no small print

> How wattiot protects your plant data: isolation per installation, TLS 1.3, X.509 certificates and per-plant permissions. Status of ISO/IEC 27001 and GDPR.

**Trust Center**

How we protect your plant data, where our compliance stands, and who to write to if you find a security problem.

## How we protect your plant’s data

The same scheme on every installation: per-device identity, encryption in transit and per-plant permissions. No exceptions by customer or by plan.

### Isolation per installation

Every plant works with its own instance, its own keys and its own permissions. One installation's data shares neither storage nor credentials with another's.

### End-to-end encryption

TLS 1.3 and AES-256 from the gateway to the platform. Data leaves the edge encrypted and travels encrypted the whole way, multi-plant deployments included.

### Per-device identity

Every edge authenticates with its own X.509 certificate and mutual authentication: the platform verifies the device and the device verifies the platform. Revoking a certificate withdraws that unit's access.

### Access by plant and by person

Permissions are set per installation and per user: each person reaches only the plants and areas that concern them.

### Continuity with no data loss

If the connection drops, the edge buffers readings locally and resends them once it is back. The plant keeps operating locally and no measurement is lost.

### Data ownership and portability

The data your plant generates is yours. We work on open standards such as MQTT, OPC-UA and Modbus, and you can export your history or ask for its deletion whenever you want.

## Certifications and standards

We publish the real status of each standard, including what is still in progress.

| Standard | Status |
| --- | --- |
| ISO/IEC 27001 | In progress |
| GDPR readiness | Compliant |

### ISO/IEC 27001

The international standard for information security management. wattiot is going through certification: we will publish the certificate and its scope on this page as soon as it is issued.

### GDPR readiness

We process personal data in line with the General Data Protection Regulation: a defined legal basis, minimisation, bounded retention periods, and rights of access, rectification, erasure and portability.

## Get in touch

- Security queries and vendor questionnaires: hello@wattiot.io
- Report a vulnerability: hello@wattiot.io — include the steps to reproduce it and the observed impact. We welcome responsible disclosure and take no action against anyone researching in good faith.
- Privacy and personal data: hello@wattiot.io · https://wattiot.io/en/privacy/

---

- Equivalent HTML page: https://wattiot.io/en/trust-center/
- Agent index: https://wattiot.io/en/llms.txt · https://wattiot.io/en/agents.md
- Sitemap: https://wattiot.io/sitemap-index.xml
