Two certified devices at the cell: an industrial PC for expert remote support, and an IEC 62443 edge gateway for Performance Data Analytics. All connections are outbound-only. Every certificate below opens the source.
Vendor ISO 27001, SOC 2, and IEC 62443 attestations, hosting, and how remote access is controlled — source certificates open below. Firewall destinations are on the IT page.
Outbound-only remote support via NinjaOne RMM. Huntress EDR protects every field PC with managed detection and response. ISO 27001 and SOC 2 Type 2 through NinjaOne; SOC 2 Type 2 through Huntress.
PLC tags and timestamps, outbound MQTT over TLS to IXON Cloud. ISO 27001, 27017, 27701 and IEC 62443 certified. SOC 2 Type 2 at the hosting layer.
Two independent paths at the cell. Neither requires a tie-in to your domain. Machine telemetry is handled in a certified cloud; camera footage stays on site.
These are the same Path 1 and Path 2 flows from Why PSS, at full size for the security review. Click any node to pause and read the control. Path 1 plays a remote session continuously — including optional local approval at the cell. Physical cabling at the cell is on Why PSS.
Machine networks terminate on isolated interfaces of the panel and are never bridged to your corporate network. The panel dials out; nothing dials in. Destinations and ports are on the IT page.
The Edge Gateway makes outbound-only encrypted MQTT + HTTPS connections — no inbound ports. In most cases it shares the same drop as remote support. Destinations are on the IT page. It collects booleans, numeric process values, strings (part numbers, batch codes, operator IDs) and timestamps: no image data, no credentials, no PII. You own the data, and permission to share it is never assumed.
FQDNs, TCP 443 and 7075, TLS-inspection exclusions, and Windows port 80 are on IT — the page to forward to a firewall owner. This heading is kept so older /trust#network links still land somewhere useful.
Each card opens the published certificate or vendor trust center.
Remote support and Performance Data Analytics are independently certified. Source documents are linked from the table.
| Control / evidence | Remote supportNinjaOne RMM + Huntress EDR + industrial PC | Performance Data AnalyticsIXON Cloud + edge gateway |
|---|---|---|
| ISO/IEC 27001 | CertifiedNinjaOne · Schellman 2025 |
CertifiedIXON B.V. · 04188640 · NCI · to Jan 2028 |
| Statement of Applicability | On requestNinjaOne resources |
On requestIXON |
| SOC 2 Type 2 | CertifiedNinjaOne 2025 · Huntress (EDR) — trust.huntress.com |
CertifiedSOC 2 Type 2 at IXON Cloud hosting providers |
| Managed EDR | DeployedHuntress on every PSS field PC · Trust Center |
N/APerformance Data Analytics path uses the IEC 62443 gateway |
| IEC 62443-4-1 / 4-2 | Support pathNinjaOne RMM + Huntress EDR + industrial PC |
CertifiedIXON edge gateway |
| External testing | AnnualNinjaOne and Huntress third-party penetration tests |
OngoingWeekly scans plus regular pentests of Cloud and gateway |
IXON Cloud runs in ISO 27001 and SOC 2 certified facilities. Relay servers carry encrypted session traffic only. Each name below opens that provider’s public compliance page.
Machine experts connect through NinjaOne with corporate identity and 2FA. Huntress EDR runs on every field PC. Every session is logged. Local approval at the cell is available when you want it.
Access to NinjaOne is through our corporate identity provider. No standalone local accounts. 2FA is enforced.
Engineers get named endpoints by role — not fleet-wide access. Sessions are logged and auditable in NinjaOne.
When someone leaves, platform access is revoked with their corporate identity. No orphaned RMM credential.
Every PSS PC in the field runs Huntress managed detection and response alongside NinjaOne — threat hunting, persistence checks, and 24/7 SOC coverage on the endpoint.
A person at the cell can be required to accept an on-screen prompt before any remote session starts.
The industrial PC can be domain-joined and imaged to your baseline, while remaining a dedicated cell device so OT/IT isolation stays in place.
We maintain gateway firmware, IXON users, and the data model. You keep WAN firewall policy, DNS allowlisting, and TLS-inspection exclusions. Destinations are on the IT page.
Vendor trust centers and published PDFs first. Path 1 and Path 2 are on this page under How it connects.
Short answers first. Path 1 and Path 2 are in How it connects, above.
Why PSS is the operations pitch. Trust Center is certificates and access control. IT is destinations and ports for the firewall team.
Need a certificate file, Statement of Applicability, or an architecture walkthrough? Contact us — we will provide it.
jamesa@truelightvision.com · 519-268-8563 · proximitysmartsupport.com
TrueLight Machine Vision Solutions Inc. · A BOS Innovations company · 2335 Discovery Dr., London, ON