NEWGridLyt v2.0: AI fault explanation now available on all plans. See what's new
SECURITY

Enterprise-grade security for critical infrastructure data.

GridLyt is built for operators who treat fleet telemetry as sensitive operational data. Our security posture aligns with SOC 2 Type 2 controls and end-to-end encryption.

Data encryption

All traffic is encrypted in transit with TLS. Fleet telemetry, anomaly records, and customer configuration data are encrypted at rest. Secrets and API tokens are stored using industry-standard key management practices.

Access control

Role-based access control (RBAC) limits permissions by team, site, and asset group. API tokens are scoped per integration and can be revoked at any time. Administrative actions are auditable.

Infrastructure security

Production workloads run on hardened cloud infrastructure with network segmentation, continuous monitoring, and least-privilege service accounts. We apply security patches on a defined cadence and isolate customer environments where required by plan.

Compliance posture

GridLyt maintains a SOC 2 Type 2–aligned control set covering security, availability, and confidentiality. Enterprise plans can include additional contractual commitments for private cloud, SSO, and custom retention policies.

Operational practices

  • Signed webhook deliveries with HMAC verification
  • Token-scoped API access (read-only or read-write)
  • Environment separation for production and sandbox
  • Incident response and customer notification procedures
  • Vendor and subprocessors reviewed under contractual controls

Need a security review?

Request a demo and ask for our security overview, or contact info@gridlyt.com for questionnaires, DPAs, and enterprise security discussions.

Request Demo