Technology / Security and deployment
Built for operators who get audited.
Energy and water operators, and their suppliers, answer security questionnaires under NIS2. Here is how BOX2M handles access, data and devices, in the form your questionnaire asks for it.
Quick answers
Security at a glance.
BOX2M runs as a second, independent path on site. It doesn't need access to the site's IT network or SCADA, which keeps the attack surface small and the operator's own systems untouched.
| Topic | BOX2M |
|---|---|
| Access control | Per-user rights, multi-tenant separation, MFA |
| Audit trail | Every login, change and command logged |
| Commands | PIN-protected on/off and setpoints; playbooks logged |
| Device to platform | MQTT over TLS; HTTPS for gateways |
| Platform to your systems | M2M API |
| Device security | “Falx class” local security mechanism; registered MØ firmware |
| Provisioning | BOX2M Build & Test platform; every configuration lab-tested |
| Architecture | Decentralised: independent of site IT and SCADA |
| Deployment | BOX2M cloud, private cloud or on-premises |
| Data retention | Retention and archiving per contract |
| Hosting | BOX2M cloud, operated by BOX2M; or a private cloud on your premises |
| Backups, availability, certifications | Answered in your supplier security questionnaire, on request |
Next step
Send us your questionnaire.
We fill in supplier security questionnaires for operators and their auditors.