Security engineered in — not appended.
Defense-in-depth across identity, transport, application, and audit layers.
Six layers of defense.
Identity & access
Four cumulative operational roles; per-resource privileges; 2FA (authenticator + recovery codes); configurable password policy; lockout on failed attempts.
Session governance
Sliding idle timeout + absolute session lifetime, server-side enforced; secure cookies (HttpOnly, strict same-site, HTTPS-only).
Transport
HTTPS/TLS to every browser; authenticated, certificate-based service-to-service channels with API keys and operator context on every call.
Web hardening
Security headers, content security policy, HSTS, request forgery protection.
Data protection
Encrypted project/screen files (AES); certificate-store-based key management.
Audit
Login/access logs, security event log, sensitive page access log, and operator action audit (user, workstation, timestamp, comment).
Secure development: ISO 9001:2015 processes, institutionalized SDLC, 100% verification & validation compliance. Responsible disclosure: see our security disclosure and vulnerability reporting policy.
Frequently asked questions
Is two-factor authentication supported?
Yes — authenticator-app 2FA with recovery codes.
What exactly is audited?
Logins and access (with client details), security events, sensitive page access, and every operator action — attributed to user, workstation, and timestamp.
Is web access safe for OT environments?
Role-scoping, encryption, complete audit, and session policy — plus fewer unpatched thick clients than a traditional installed-client fleet.
Can SCAIQ™ run fully on-premise, isolated?
Yes.
Request a security briefing.
Bring your toughest SCADA questions. Our engineers will show you real screens, real alarms, and real trends.
Or talk to us directly: +91 84014 22388 ·sales@scaiq.com