Security

HartBeat is built for OT teams who need remote instrument work to be controlled, attributable, and provable. It is designed toward SOC 2 controls and built with IEC 62443 and NIST SP 800-82 principles in mind. We don’t claim certifications we don’t hold.

Our security posture

  • Outbound-only site connectivity

    The site connector reaches out. No inbound openings to the plant network.

  • Encrypted, mutually authenticated connections

    Between site and cloud, both sides prove who they are.

  • Identity-based access

    Personal sign-in, scoped roles, and lockout after repeated failed sign-ins.

  • Tamper-evident audit record

    A digitally signed record of every HartBeat-mediated interaction, each record chained to the one before it.

  • Strict isolation between organizations

    Enforced in more than one layer.

  • Administrators are accountable too

    Privileged actions are recorded, and don’t happen if they can’t be recorded.

  • Secure development practice

    Every change is reviewed and automatically checked, including continuous vulnerability scanning.

  • Website separated from the product

    This website holds no product credentials and has no path into the application. Sign-in happens at core.hartbeat.app.

Your site, HartBeat, your people

The connector at your site makes an outbound, encrypted connection to HartBeat. Your people reach instruments through a governed HartBeat session, from their browser and their usual tools. The detailed architecture is available under NDA.

HartBeat architecture overview Three areas. Your site holds field instruments, a gateway, and the HartBeat connector. The connector makes an outbound, encrypted connection to HartBeat. Your people reach instruments through a governed HartBeat session from their browser and their usual tools. Your site LT204 PT101 FT201 Gateway Connector outbound, encrypted HartBeat secure cloud signed record governed session Your people m.chenEngineer Browser and their tools 2.84 m HartBeat architecture overview Three areas, top to bottom. Your site holds field instruments, a gateway, and the HartBeat connector. The connector makes an outbound, encrypted connection to HartBeat. Your people reach instruments through a governed HartBeat session from their browser and their usual tools. Your site LT204 PT101 FT201 Gateway Connector outbound, encrypted HartBeat secure cloud signed record governed session Your people m.chenEngineer Browser and their tools 2.84 m

Illustration. Fictional site, people, and readings.

Separated by design

Each customer is its own organization.

One organization per customer, strictly isolated from every other, enforced in more than one independent layer so a single mistake can’t expose another customer’s data. Service providers and integrators can run each client in its own isolated organization, so client data never mixes.

Operators are accountable.

HartBeat staff set up organizations and their first administrator, and handle suspension and closure. They don’t browse customer data casually: any operator action on a customer organization is a deliberate, signed, recorded event, and if that record can’t be written, the action doesn’t happen.

Roles have limits.

Administrators manage their own organization, and nothing in the product lets anyone escalate beyond it.

Data storage and retention

How HartBeat stores and keeps your data
Topic Our position
Where records live In HartBeat’s secure cloud, in a dedicated, append-only, tamper-evident store. Customers don’t run storage.
How long we keep audit records For the life of your account. Records are never deleted because of their age.
Export Administrators and auditors can export audit records at any time.
When an account closes Field access is cut first. You receive your records. We then hold the data for a 180-day closing period, after which it is permanently deleted.
Suspension A suspended account keeps all of its data and returns intact when reactivated. Cancellation never triggers an immediate hard delete.
Secrets Credentials, tokens, and signing material never appear in logs, by policy, and that policy is checked automatically.
Data minimization We keep what’s needed to operate and prove access: identities, devices, sessions, commands, and decisions.
Audit records are kept for the life of your account. When an account closes, field access ends and you receive your records; HartBeat then holds the data for a 180-day closing period, after which it is permanently deleted. For the life of your account Records are never deleted because of their age Account closes Field access ends; you receive your records 180-day closing period Permanently deleted

Questions security reviewers ask

Do we have to open our network to the internet?

No. The site connector makes an outbound connection; nothing needs to accept inbound traffic from the internet.

Can the audit record be altered?

Any edit, deletion, or reordering is detectable, because every record is signed and linked to the one before it.

Can HartBeat block a command?

HartBeat evaluates every command against your access policy and permanently records the decision and outcome. Enforcing mode, where out-of-policy commands are withheld, is on our roadmap.

Is our data separated from other customers’?

Yes. Every organization is strictly isolated, enforced in more than one layer.

How long do you keep our records?

For as long as you’re a customer. If you leave, you get your records first; we hold them for a 180-day closing period and then delete them permanently.

Is HartBeat SOC 2 or IEC 62443 certified?

HartBeat is designed toward SOC 2 controls and built with IEC 62443 and NIST SP 800-82 principles in mind. We don’t claim certifications we don’t hold.

Need more depth?

We don’t publish ports, protocols, cryptographic details, or hosting details. Security reviewers can request an architecture review under NDA.

Request an architecture review under NDA

Set up a trial with our team.

Contact sales to set up a trial: for distributed operators, service teams, and instrumentation groups ready to evaluate governed remote HART access.