Security
A machine observer with explicit boundaries.
The current product is built around authenticated device ingest, workspace-scoped operator access and an observable record of missing as well as received data.
Product controls
- Operators authenticate before workspace records are available.
- Firestore rules scope machine records to the signed-in workspace owner in the current local product.
- Gateway credentials are shown once; the server stores a cryptographic hash rather than the plaintext key.
- Telemetry keeps its device identity and receive timestamp so gaps remain visible.
- The product observes hardware; it does not replace certified control or safety systems.
Deployment boundary
Encryption, hosting geography, backups, incident response and availability commitments depend on the selected production environment and belong in its signed service agreement. This page does not claim certifications the product has not earned.
Report an issue
Send a concise description and reproduction steps to security@sutrace.io. Do not test against machines, accounts or workspaces you do not own or administer.
Product information only. Customer-specific commitments belong in the signed order and service agreement.