PSS TRUST CENTER · SECURITY & COMPLIANCE

Security and compliance for Proximity Smart Support.

Two certified devices at the cell: an industrial PC for expert remote support, and an IEC 62443 edge gateway for machine analytics. All connections are outbound-only. Every certificate below opens the source.

ISO 27001, SOC 2, IEC 62443, hosting attestations, and how remote access is controlled — source certificates open below.

View certificates
Support path

OnLogic industrial PC + NinjaOne

Outbound-only remote support. Machine experts connect to that panel over TLS — no inbound ports, no VPN. ISO 27001 and SOC 2 Type 2 certified through NinjaOne.

Analytics path

IXON edge gateway + IXON Cloud

PLC tags and timestamps, outbound MQTT over TLS to IXON Cloud. ISO 27001, 27017, 27701 and IEC 62443 certified. SOC 2 Type 2 at the hosting layer.

Architecture

Designed for plant networks and a clean security review.

Two independent paths at the cell. Neither requires a tie-in to your domain. Machine telemetry is handled in a certified cloud; camera footage stays on site.

Certified product stackRemote support and analytics run on ISO 27001, SOC 2, and IEC 62443 certified platforms — with source certificates one click away.
Machine data onlyTag values and timestamps. No business documents, drawings, credentials, or personal data.
Outbound onlyBoth devices dial out over TLS. No inbound firewall rules and no VPN concentrator.
OT-grade hardwareThe edge gateway is IEC 62443-4-1 and 4-2 certified — the standard written for this class of device.
How it connects

Two outbound-only paths. Nothing dials in.

These are the same Path 1 and Path 2 flows from Why PSS, at full size for the security review. Click any node for the control. On Path 1, press Run session to watch a connection establish — including optional local approval at the cell.

PATH 1 Remote support — how an expert reaches the line Press Run session to watch a session establish, step by step.

YOUR PLANT Machine network PLC · Robots · HMI Cameras → NVR (footage stays local) ISOLATED PSS Panel Industrial IoT PC Patch management RMM agent · EDR Local monitor (session visible lineside) Your internet drop (VLAN'd off core net) OUTBOUND ONLY TLS 443 · outbound RMM cloud relay End-to-end encrypted Session brokering Full audit log Machine expert 2FA fleet login Role-based access Remote desktop to that panel only 2FA Your representative at the cell approves each remote session on the local PC NO VPN · NO INBOUND RULES · NO PATH INTO YOUR NETWORK
Click a component — or press Run session to see the full connection sequence with narration.

Machine networks terminate on isolated interfaces of the panel and are never bridged to your corporate network. The panel dials out; nothing dials in. All you provide: one VLAN'd internet drop with outbound TCP 443 open (TCP 7075 fallback; port 80 for agent updates).

PATH 2 Performance Analytics — how machine data reaches you Same drop, same outbound-only rule — and the data comes back to your team, not ours.

YOUR PLANT Machine data PLC tags · sensors Vision · quality values · strings · timestamps NO IMAGES · NO CREDENTIALS Edge Gateway Multi-protocol Store & forward Speaks most PLCs IEC 62443 certified (buffers locally if the link drops) The same internet drop — no new rules OUTBOUND ONLY MQTT + HTTPS 443 Analytics cloud ISO 27001 data centres AES-256 at rest Retention you set Your team Browser · mobile Shift reports by email API into your MES / ERP MFA NO INBOUND PORTS · NO PII · YOUR PRODUCTION DATA STAYS YOURS
Click a component — analytics runs over the same outbound-only drop as remote support, so there is usually nothing new for your firewall team to approve.

The Edge Gateway makes outbound-only encrypted MQTT + HTTPS(443) connections — no inbound ports, and typically no firewall modifications at all. It collects booleans, numeric process values, strings (part numbers, batch codes, operator IDs) and timestamps: no image data, no credentials, no PII. You own the data, and permission to share it is never assumed.

Certificates

Certificates for every layer of the platform.

Each card opens the published certificate or vendor trust center.

Certification coverage

How ISO, SOC 2, and IEC 62443 apply to each path.

Remote support and analytics are independently certified. Source documents are linked from the table.

Control / evidence Remote supportNinjaOne + industrial PC AnalyticsIXON Cloud + edge gateway
ISO/IEC 27001
CertifiedNinjaOne · Schellman 2025
CertifiedIXON B.V. · 04188640 · NCI · to Jan 2028
Statement of Applicability
On requestIXON
SOC 2 Type 2
CertifiedNinjaOne 2025 report
CertifiedSOC 2 Type 2 at IXON Cloud hosting providers
IEC 62443-4-1 / 4-2
Support pathRMM and industrial PC
CertifiedIXON edge gateway
External testing
AnnualThird-party penetration tests
OngoingWeekly scans plus regular pentests of Cloud and gateway
Analytics data path — hosting

SOC 2 Type 2 certified hosting for machine data.

IXON Cloud runs in ISO 27001 and SOC 2 certified facilities. Relay servers carry encrypted session traffic only. Each name below opens that provider’s public compliance page.

Access control

Remote access is SSO, least privilege, and auditable.

Machine experts connect through NinjaOne with corporate identity and 2FA. Every session is logged. Local approval at the cell is available when you want it.

SSO + 2FA

Access to NinjaOne is through our corporate identity provider. No standalone local accounts. 2FA is enforced.

Least privilege

Engineers get named endpoints by role — not fleet-wide access. Sessions are logged and auditable in NinjaOne.

Instant offboarding

When someone leaves, platform access is revoked with their corporate identity. No orphaned RMM credential.

Optional local approval

A person at the cell can be required to accept an on-screen prompt before any remote session starts.

Customer-managed IPC

The industrial PC can be domain-joined and imaged to your baseline, while remaining a dedicated cell device so OT/IT isolation stays in place.

Shared operations

We maintain gateway firmware, IXON users, and the data model. You keep WAN firewall policy and DNS allowlisting.

Documents & sources

Certificates, guides, and architecture — in one place.

Vendor trust centers and published PDFs first. Path 1 and Path 2 are on this page under How it connects.

Common questions

What IT and security teams usually ask.

Short answers first. Path 1 and Path 2 are in How it connects, above.

How is the PSS stack certified?
Remote support is certified through NinjaOne (ISO/IEC 27001:2022 and SOC 2 Type 2). Analytics is certified through IXON (ISO/IEC 27001:2022, 27017, 27701, ISO 9001, and IEC 62443-4-1 / 4-2), with SOC 2 Type 2 at IXON Cloud hosting providers. Source documents are linked on this page.
Where is machine data stored?
Tag values and timestamps are stored and processed by IXON Cloud. Camera footage stays on the local NVR and is not uploaded. Dashboards are built in IXON’s platform.
Is there inbound RDP or a VPN into the plant?
No. The NinjaOne agent on the industrial PC establishes an outbound TLS connection. No inbound ports, no port forwarding, no public IP on the PSS PC. The IXON gateway is the same pattern: outbound MQTT/HTTPS only. See Path 1 and Path 2 in How it connects.
Can we manage the Windows industrial PC?
Yes. The IPC can be domain-joined, imaged, and tooled to your baseline. It remains a dedicated industrial device at the cell so OT/IT isolation stays in place. The edge gateway is the IEC 62443-4-2 certified PLC interface and is deployed as that certified device.
How is the platform tested?
NinjaOne performs annual third-party penetration testing. IXON runs weekly third-party vulnerability scans and regular penetration tests of IXON Cloud and gateway firmware. BOS also commissions independent testing of its environment.
Who completes a supplier security questionnaire?
BOS Innovations Inc. as contracting entity. Platform controls are documented against NinjaOne and IXON as the certified product stack, and this page is the source map for certificates.
Three PSS packages

Same product. Three focused views.

Why PSS covers operations, ROI, and how it connects on your line. Trust Center covers security and compliance. Digital Future covers the roadmap ahead — with PSS at the center of your lifecycle.

Ready for your IT and security team.

Need a certificate file, Statement of Applicability, or an architecture walkthrough? Contact us — we will provide it.

James Aitken · Proximity Smart Support™ Product Manager

jamesa@truelightvision.com  ·  519-268-8563  ·  proximitysmartsupport.com

TrueLight Machine Vision Solutions Inc. · A BOS Innovations company · 2335 Discovery Dr., London, ON

QR code — open Why PSS on your phone Scan Why PSS