Security

Security and privacy at Service Insight

Customers trust Service Insight with the records behind their equipment, maintenance and monitoring. This page explains how we protect that data: how it is encrypted, where it runs, who can reach it, how we build and test the platform, and how we respond if something goes wrong.

Governance

A security program built on clear principles

Service Insight sets policies and controls, monitors them continuously, and has them assessed by an independent auditor through our SOC 2 program.

01

Least privilege

People and systems get only the access their role needs, and that access is removed when it is no longer needed.

02

Defense in depth

Controls are layered across the network, the application and our people, so no single failure exposes customer data.

03

Consistency

The same controls apply to every environment, team and vendor that touches customer data.

04

Continuous improvement

We review our controls regularly and strengthen them as the platform, our customers and the threat landscape change.

SOC 2 Type II

We run our SOC 2 Type II compliance program in Vanta. Vanta monitors our security controls continuously, tracks our policies, employee training and vendor reviews, and collects the evidence our independent auditor tests, so issues are found and fixed as they happen rather than once a year.

SOC 2 Type II programContinuous monitoring in Vanta

Built for regulated labs

Our customers work in GxP and non-GxP labs. The platform supports their compliance with audit trails on asset, maintenance and calibration records, electronic signatures and validation workflows designed for 21 CFR Part 11.

21 CFR Part 11 support
Data protection

Customer data is encrypted and kept separate

Your asset records, maintenance history and sensor data belong to you. We protect them at every stage, from the device to the database.

Data in transit

All traffic between browsers, mobile devices, integrations and the platform is encrypted with TLS 1.2 or higher.

Data at rest

Databases, file storage and backups that hold customer data are encrypted at rest with AES-256.

Keys and secrets

Encryption keys are managed in AWS Key Management Service. Application secrets are stored encrypted in AWS secrets management services, never in source code, and access to them is tightly restricted.

Tenant isolation

Service Insight is a multi-tenant platform. Every record is tied to its customer organization, and the application enforces that boundary so customers cannot see each other's data.

Backups and resilience

Customer data is backed up automatically, and backups are encrypted. Production runs across multiple AWS availability zones so that a single facility failure does not take the platform down.

Retention and deletion

We retain customer data for as long as our agreements require, generally three years. When a customer leaves, we return or delete their data as their agreement specifies.

Infrastructure and IoT

Hosted on AWS, secured from device to cloud

The platform and the monitoring network that feeds it are designed so that devices add visibility to your lab without adding risk to your network.

Cloud infrastructure

Service Insight runs on Amazon Web Services, whose data centers hold SOC 1, SOC 2 and ISO 27001 certifications for physical and environmental security. Our production environment sits in private networks with firewall rules that expose only the services customers need.

Encrypted wireless devices

Our devices communicate over LoRaWAN, which encrypts every message with AES-128 at both the network and the application layer, with unique keys for each device.

Pre-registered gateways

Every gateway is registered with our AWS servers before it ships and authenticates with security certificates, so only known, trusted gateways can send data to the platform.

Outbound-only connections

Gateways open outbound connections only and accept no inbound traffic, so they need no open ports on your network. Cellular failover keeps monitoring running if your network goes down.

Product security

Security built into how we develop

Every change to the platform passes through a controlled development process before it reaches customers.

Secure development lifecycle

  • Every code change is reviewed before it is merged.
  • Development, test and production environments are kept separate, and production data is not used for development.
  • Releases go through automated testing and a controlled deployment process.
  • Engineers are trained in secure coding practices.

Vulnerability management

  • Third-party dependencies are scanned for known vulnerabilities.
  • Infrastructure is scanned for vulnerabilities on a regular schedule.
  • Findings are tracked and fixed within defined timeframes based on severity.

Logging and monitoring

We log activity across the application and infrastructure, and alert our team to unusual behavior so it can be investigated quickly.

Responsible AI

Cortex, our AI layer, works within the same tenant boundary and access controls as the rest of the platform: it only uses data the signed-in user is allowed to see. Customer data is not used to train third-party AI models.

Access control

The right people, and only the right people

Customers control who can do what in their account, and we strictly control our own team's access to production.

For your team

  • Role-based permissions, administered by your own administrators.
  • Single sign-on with your identity provider, such as Microsoft Entra ID.
  • Audit trails that record who changed what, and when.
  • Electronic signatures for approvals that require them.

For our team

  • Access to production is limited to the employees who need it to run the service.
  • Multi-factor authentication is required for our critical systems.
  • Access is reviewed regularly and removed promptly when someone changes role or leaves.
  • Our team accesses customer data only to provide support or operate the service.
Corporate security

A security-aware team

Strong technology controls depend on the people and vendors around them.

People

Employees pass background checks before they join, accept our security policies, and complete security awareness training when they start and every year after.

Devices

Company laptops are monitored for security configuration, including disk encryption, screen lock, up-to-date operating systems and anti-malware protection.

Vendors

We assess vendors by the data and systems they can reach, review their security before we use them, and revisit higher-risk vendors regularly.

Policies

Written policies cover information security, access control, data management, change management, incident response and business continuity. They are reviewed at least once a year.

Incident response

Prepared to respond, and to keep running

If something goes wrong, we have a plan for containing it, telling the people affected, and restoring service.

Incident response

A documented incident response plan defines how we detect, triage, contain and recover from security incidents. If an incident affects customer data, we notify affected customers without undue delay and as their agreements require, and we review every incident to prevent it happening again.

Business continuity

Our business continuity and disaster recovery plans cover how we restore the platform and its data from backups. We test them regularly.

Privacy

Privacy and transparency

We collect only what we need to run the service, and we are open about how we handle it.

Privacy policy

Read how we collect, use and protect personal information in our privacy policy.

Agreements and subprocessors

A data processing agreement and our list of subprocessors are available on request. Contact security@serviceinsight.io.

Report a vulnerability

If you believe you have found a security issue in Service Insight, email security@serviceinsight.io. We investigate every report and will keep you informed.

Security reviews and questionnaires: email security@serviceinsight.io for more information. This page is reviewed at least once a year, and was last updated on October 2, 2026.

Running a security review?

Our team will send completed questionnaires and our policies, and answer your security team's questions.