PSS TRUST CENTER · SECURITY & COMPLIANCE

Security and compliance for Proximity Smart Support.

Two certified devices at the cell: an industrial PC for expert remote support, and an IEC 62443 edge gateway for Performance Data Analytics. All connections are outbound-only. Every certificate below opens the source.

Vendor ISO 27001, SOC 2, and IEC 62443 attestations, hosting, and how remote access is controlled — source certificates open below. Firewall destinations are on the IT page.

Support path

OnLogic industrial PC + NinjaOne + Huntress

Outbound-only remote support via NinjaOne RMM. Huntress EDR protects every field PC with managed detection and response. ISO 27001 and SOC 2 Type 2 through NinjaOne; SOC 2 Type 2 through Huntress.

Performance Data Analytics path

IXON edge gateway + IXON Cloud

PLC tags and timestamps, outbound MQTT over TLS to IXON Cloud. ISO 27001, 27017, 27701 and IEC 62443 certified. SOC 2 Type 2 at the hosting layer.

Architecture

Designed for plant networks and a clean security review.

Two independent paths at the cell. Neither requires a tie-in to your domain. Machine telemetry is handled in a certified cloud; camera footage stays on site.

Certified product stackRemote support (NinjaOne + Huntress EDR) and Performance Data Analytics run on ISO 27001, SOC 2, and IEC 62443 certified platforms — with source certificates one click away.
Machine data onlyTag values and timestamps. No business documents, drawings, credentials, or personal data.
Outbound onlyBoth devices dial out over TLS. No inbound firewall rules and no VPN concentrator. Destinations and ports are on the IT page.
OT-grade hardwareThe edge gateway is IEC 62443-4-1 and 4-2 certified — the standard written for this class of device.
How it connects

Two outbound-only paths. Nothing dials in.

These are the same Path 1 and Path 2 flows from Why PSS, at full size for the security review. Click any node to pause and read the control. Path 1 plays a remote session continuously — including optional local approval at the cell. Physical cabling at the cell is on Why PSS.

PATH 1 Remote support — how an expert reaches the line A remote session plays continuously. Click a component to pause and read. Toggle Local approval to see the cell-side prompt.

YOUR PLANT Machine network PLC · Robots · HMI Cameras → NVR (footage stays local) ISOLATED PSS Panel Industrial IoT PC Patch management NinjaOne · Huntress Local monitor (session visible lineside) Your internet drop (VLAN'd off core net) OUTBOUND ONLY TLS 443 · outbound NinjaOne cloud relay End-to-end encrypted Session brokering Full audit log Machine expert 2FA fleet login Role-based access Remote desktop to that panel only 2FA Your representative at the cell approves each remote session on the local PC NO VPN · NO INBOUND RULES · NO PATH INTO YOUR NETWORK
Click a component to pause and read. The remote-session sequence plays on a loop.

Machine networks terminate on isolated interfaces of the panel and are never bridged to your corporate network. The panel dials out; nothing dials in. Destinations and ports are on the IT page.

PATH 2 Performance Data Analytics — how machine data reaches you Same drop, same outbound-only rule — click a component to pause and read.

YOUR PLANT Machine data PLC tags · sensors Vision · quality values · strings · timestamps NO IMAGES · NO CREDENTIALS Edge Gateway Multi-protocol Store & forward Speaks most PLCs IEC 62443 certified (buffers locally if the link drops) The same internet drop — no new rules OUTBOUND ONLY MQTT + HTTPS 443 Performance Data Analytics ISO 27001 data centres AES-256 at rest Retention you set Your team Browser · mobile Shift reports by email API into your MES / ERP MFA NO INBOUND PORTS · NO PII · YOUR PRODUCTION DATA STAYS YOURS
Click a component to pause and read — Performance Data Analytics runs over the same outbound-only drop as remote support. Destinations are on the IT page.

The Edge Gateway makes outbound-only encrypted MQTT + HTTPS connections — no inbound ports. In most cases it shares the same drop as remote support. Destinations are on the IT page. It collects booleans, numeric process values, strings (part numbers, batch codes, operator IDs) and timestamps: no image data, no credentials, no PII. You own the data, and permission to share it is never assumed.

Network requirements

Destinations and ports moved to the IT page.

FQDNs, TCP 443 and 7075, TLS-inspection exclusions, and Windows port 80 are on IT — the page to forward to a firewall owner. This heading is kept so older /trust#network links still land somewhere useful.

Open IT requirements

Certificates

Certificates for every layer of the platform.

Each card opens the published certificate or vendor trust center.

Certification coverage

How ISO, SOC 2, and IEC 62443 apply to each path.

Remote support and Performance Data Analytics are independently certified. Source documents are linked from the table.

Control / evidence Remote supportNinjaOne RMM + Huntress EDR + industrial PC Performance Data AnalyticsIXON Cloud + edge gateway
ISO/IEC 27001
CertifiedNinjaOne · Schellman 2025
CertifiedIXON B.V. · 04188640 · NCI · to Jan 2028
Statement of Applicability
On requestIXON
SOC 2 Type 2
CertifiedNinjaOne 2025 · Huntress (EDR) — trust.huntress.com
CertifiedSOC 2 Type 2 at IXON Cloud hosting providers
Managed EDR
DeployedHuntress on every PSS field PC · Trust Center
N/APerformance Data Analytics path uses the IEC 62443 gateway
IEC 62443-4-1 / 4-2
Support pathNinjaOne RMM + Huntress EDR + industrial PC
CertifiedIXON edge gateway
External testing
AnnualNinjaOne and Huntress third-party penetration tests
OngoingWeekly scans plus regular pentests of Cloud and gateway
Performance Data Analytics data path — hosting

SOC 2 Type 2 certified hosting for machine data.

IXON Cloud runs in ISO 27001 and SOC 2 certified facilities. Relay servers carry encrypted session traffic only. Each name below opens that provider’s public compliance page.

Access control

Remote access is SSO, least privilege, and auditable.

Machine experts connect through NinjaOne with corporate identity and 2FA. Huntress EDR runs on every field PC. Every session is logged. Local approval at the cell is available when you want it.

SSO + 2FA

Access to NinjaOne is through our corporate identity provider. No standalone local accounts. 2FA is enforced.

Least privilege

Engineers get named endpoints by role — not fleet-wide access. Sessions are logged and auditable in NinjaOne.

Instant offboarding

When someone leaves, platform access is revoked with their corporate identity. No orphaned RMM credential.

Huntress EDR

Every PSS PC in the field runs Huntress managed detection and response alongside NinjaOne — threat hunting, persistence checks, and 24/7 SOC coverage on the endpoint.

Optional local approval

A person at the cell can be required to accept an on-screen prompt before any remote session starts.

Customer-managed IPC

The industrial PC can be domain-joined and imaged to your baseline, while remaining a dedicated cell device so OT/IT isolation stays in place.

Shared operations

We maintain gateway firmware, IXON users, and the data model. You keep WAN firewall policy, DNS allowlisting, and TLS-inspection exclusions. Destinations are on the IT page.

Documents & sources

Certificates, guides, and architecture — in one place.

Vendor trust centers and published PDFs first. Path 1 and Path 2 are on this page under How it connects.

Common questions

What IT and security teams usually ask.

Short answers first. Path 1 and Path 2 are in How it connects, above.

How is the PSS stack certified?
Remote support is certified through NinjaOne (ISO/IEC 27001:2022 and SOC 2 Type 2). Endpoint security on every PSS field PC is Huntress EDR (SOC 2 Type 2 — see trust.huntress.com). Performance Data Analytics is certified through IXON (ISO/IEC 27001:2022, 27017, 27701, ISO 9001, and IEC 62443-4-1 / 4-2), with SOC 2 Type 2 at IXON Cloud hosting providers. Source documents are linked on this page.
How is the PSS panel protected at the endpoint?
Every PSS PC in the field runs Huntress EDR for managed detection and response, alongside NinjaOne for remote management and patching. Huntress provides 24/7 threat hunting and persistence monitoring on the Windows 11 IoT industrial PC. Certificates and reports: trust.huntress.com.
Where is machine data stored?
Tag values and timestamps are stored and processed by IXON Cloud. Camera footage stays on the local NVR and is not uploaded. Dashboards are built in IXON’s platform.
Is there inbound RDP or a VPN into the plant?
No. The NinjaOne agent on the industrial PC establishes an outbound TLS connection. No inbound ports, no port forwarding, no public IP on the PSS PC. The IXON gateway is the same pattern: outbound MQTT/HTTPS only. Destinations and ports are on the IT page. See Path 1 and Path 2 in How it connects.
Can we manage the Windows industrial PC?
Yes. The IPC can be domain-joined, imaged, and tooled to your baseline. It remains a dedicated industrial device at the cell so OT/IT isolation stays in place. The edge gateway is the IEC 62443-4-2 certified PLC interface and is deployed as that certified device.
How is the platform tested?
NinjaOne and Huntress each perform third-party penetration testing (reports available from their trust centers). IXON runs weekly third-party vulnerability scans and regular penetration tests of IXON Cloud and gateway firmware. BOS also commissions independent testing of its environment.
Who completes a supplier security questionnaire?
BOS Innovations Inc. as contracting entity. Platform controls are documented against NinjaOne (RMM), Huntress (EDR), and IXON as the certified product stack, and this page is the source map for certificates.
Three PSS packages

Same product. Three focused views.

Why PSS is the operations pitch. Trust Center is certificates and access control. IT is destinations and ports for the firewall team.

Ready for your IT and security team.

Need a certificate file, Statement of Applicability, or an architecture walkthrough? Contact us — we will provide it.

James Aitken · Proximity Smart Support™ Product Manager

jamesa@truelightvision.com  ·  519-268-8563  ·  proximitysmartsupport.com

TrueLight Machine Vision Solutions Inc. · A BOS Innovations company · 2335 Discovery Dr., London, ON

QR code — open Why PSS on your phone Scan Why PSS