Industrial connectivity without losing control of data, access or machine boundaries.
This page describes the security and deployment principles INAINEX engagements are designed around. Final controls depend on the selected deployment, customer IT/OT policies and agreed project scope.
Customer data ownership
Project agreements should define who owns operational data, documents, integrations and exported records. INAINEX should not depend on ambiguous ownership.
Role-based access
Users should only see and perform actions required by their role, site and responsibility. Approval rights should be enforced in the application, not only hidden in the UI.
IT / OT boundaries
Machine connectivity should respect plant network segmentation, approved gateways, firewall rules and controlled command paths.
Integration failure handling
Interfaces should define acknowledgements, timeouts, retry behaviour, offline queues and safe recovery rather than silently dropping events.
Deployment choices
Cloud, private-cloud, edge or on-premise patterns can be evaluated based on latency, connectivity, IT policy and machine-control requirements.
Auditability
Critical business and machine actions should retain user, timestamp, status and source context so investigations do not depend on memory.
What should be confirmed for every implementation.
| Area | Questions to confirm | Why it matters |
|---|---|---|
| Identity | How are users authenticated? Is MFA or SSO required? How are service accounts controlled? | Prevents uncontrolled access. |
| Authorisation | Which roles can view, create, edit, approve, post or issue machine-affecting commands? | Separates responsibility from convenience. |
| Data location | Where is the database/file store hosted and who administers it? | Clarifies ownership and residency expectations. |
| Network | How do ERP/cloud networks reach gateways, PLCs or machines? Which ports and directions are allowed? | Reduces OT exposure. |
| Backup / recovery | What is backed up, how often, and how is restore tested? | Recovery must be designed, not assumed. |
| Logging | Which security, transaction and equipment events are retained and for how long? | Supports troubleshooting and accountability. |
