Security & architecture

How LIMIS connects — safely.

A reviewable, one-way, read-only architecture designed to pass IT, OT, and security review. Control systems stay inside their existing boundary. This page is the artifact your technical team can forward internally.

Architecture

One-way, outbound from approved sources.

LIMIS reads from an approved endpoint and presents context in the workflow layer. There is no inbound path to control systems.

Plant control layerSCADA / DCS / PLC — stays inside its existing boundary. No LIMIS access.
Approved endpointHistorian or integration service exposes reviewed data through a scoped service account.
LIMIS ConnectOne-way, read-only bridge. No writeback, no commands.
Workflow layerOperators and leaders see approved context inside rounds, logsheets, and reviews.

Arrows flow left to right only. A detailed data-flow diagram is included in the downloadable brief.

Security posture

Controls your security team expects.

The specifics below are written for a security questionnaire and technical review.

Encryption

Data encrypted in transit (TLS 1.2+) and at rest (AES-256).

Access & identity

Role-based access across IT, OT, operations, quality, and leadership. SSO / SAML available on enterprise plans.

Scoped service account

Source access uses a least-privilege, read-only service account or equivalent reviewed integration pattern.

Audit logging

Submissions, reviews, role changes, exceptions, and timestamps are logged and traceable.

Certifications & compliance

Third-party validation.

Independent assurance, not just our own assertions.

SOC 2 Type II[In progress — target date]
ISO 27001[Planned / achieved]
IEC 62443[Aligned to OT security practice]
Penetration testing[Annual / summary available]

Regulated environments

For food & beverage and pharma-adjacent lines: support for 21 CFR Part 11 controls, electronic signatures, and a GxP-ready audit trail.

Data residency

Hosted in [region] with options for [additional regions].

Deployment

Where it runs, and where your data lives.

Deployment is one of the first questions an OT team asks. Here are the options.

Cloud SaaS

Default. Hosted on [cloud provider, region], with a dedicated tenant for your data.

On-prem / private

Available for sites that require data to stay within their own network. [Confirm availability.]

Edge / offline

Field capture works offline in dead zones and syncs when connectivity returns. Air-gapped options on request.

Ownership & exit

Your data is yours.

No lock-in. The terms of getting your data out are defined before you start.

Ownership

The customer owns all submitted records and context. LIMIS presents approved data under the agreed model.

Export

Standard export to [CSV / API / other] is included, so records remain usable outside LIMIS.

Offboarding

On exit, data is exported and then deleted per the agreed retention and deletion terms.

Uptime & support

Availability target and support response times are defined per plan. See Pricing.

Technical review

Bring your security team.

We are built to be reviewed. Request the brief, or set up a session with your IT, OT, and security stakeholders.