Security

Trust Centre

How Coneqt handles security, data ownership and access — written plainly, without claims we cannot yet evidence.

Last updated · 4 September 2026

What we will not claim

This page deliberately makes no claim to any certification, audit report or accreditation. If we hold one in future it will be named here with its scope and date, and we will provide the report on request.

Where a control is planned rather than in place, we say so. A trust page that overstates is worse than no trust page.

Your data stays yours

Machine, production, energy and maintenance data belongs to the customer. We process it to deliver the subscribed service and for nothing else.

We do not sell customer data, do not use one customer’s data to benefit another, and do not name customers or publish their figures without written agreement.

Edge-first by design

Coneqt gateways sit alongside your existing controls and read the signals your machines already produce. They do not rewrite PLC programmes and are not in the control path of the machine.

Edge components keep recording when the network or cloud link drops and resynchronise when it returns, so a connectivity failure does not become a data gap.

Access control

Access to customer environments is limited to the Coneqt engineers who need it to deliver or support the deployment. Named user accounts, role-based permissions and user management are part of the product.

Credentials are never shared between customers, and access by our team is granted for a purpose rather than standing open indefinitely.

Encryption and transport

Data in transit between the edge, the platform and your browser is encrypted using current transport security. Data at rest is stored on infrastructure that provides encryption at rest.

Specific cipher suites, key management and hosting regions are confirmed per deployment — ask and we will document what applies to yours.

Hosting and sub-processors

We use third-party infrastructure and service providers to operate the platform, each bound to process data only on our instructions. A current list is available on request, and we notify affected customers before adding a sub-processor that touches their data.

Deployments that must stay on-premise or in a specific region are scoped individually.

Data export and exit

You can get your data out. Excel and CSV export is available from Professional, and API access from Enterprise. On termination we export or delete data as instructed in your order form.

No part of our commercial model depends on making your data difficult to leave with.

Reporting a vulnerability

If you believe you have found a security issue in our software or this website, contact us before disclosing it publicly. We will acknowledge the report, tell you what we find and credit you if you would like us to.

We do not pursue researchers who report in good faith and do not access or damage customer data.

Running a vendor assessment?

Send us your security questionnaire. We answer it directly and tell you where the answer is "not yet" rather than dressing it up.

Start with one line. Scale to the whole network.

A two-week pilot on a single line, on your data, with your team. No rip-and-replace and no new hardware in most plants.

We use only what this site needs to work, plus aggregate traffic counts. No advertising trackers, and we do not sell audience data.