Security, Trust, & Compliance

Security at CastNet

At CastNet, Inc., we design and build our hardware and cloud infrastructure with security at the absolute core. From the physical device to the SaaS Command Center dashboard, we employ defense-in-depth methodologies to ensure your data, networks, and physical assets remain secure and resilient.

Our approach to security, trust, & compliance includes aligning to modern, industry-proven practices such as the following list in alphabetical order:

  • Continuous Monitoring
  • Defense-in-Depth
  • Least Privilege
  • Resilience
  • Shift-Left
  • Zero Trust

Continuous Monitoring Solution (CMS) Sensor

Our CMS Sensors are engineered to protect your environment and operate safely within or adjacent to your network.
 
  • Secure Boot & Firmware Integrity: CastNet hardware utilizes a hardware-based Root of Trust. Cryptographic signatures ensure that only authenticated, untampered firmware can execute on the device.
  • Password-protected BIOS: changes to the BIOS requires a restricted passcode.
  • Endpoint Detection & Response (EDR): CMS Sensors run an endpoint monitoring solution that protects against viruses and malware and detects suspicious activity. The endpoint is monitored 24 / 7 / 365 by a manned security operations center (SOC) empowered by Security Orchestration, Automation, and Response (SOAR) playbooks.
  • Encryption at Rest: No data is stored locally on the device, and all data stored in the cloud is encrypted.
  • Encryption in Transit: Communications between the sensor and the cloud-based Command Center are restricted to a Secure Access Service Edge (SASE) network.
  • Over-the-Air (OTA) Updates: Security patches are deployed seamlessly and securely over-the-air. Updates require mandatory cryptographic verification before installation.
  • Secure Egress Options: CMS Sensors can communicate with the Command Center using existing site infrastructure or its own cellular connection. If using existing site infrastructure, we recommend network isolation using a virtual local area network (VLAN). 
  • Passive Detection: CMS Sensors operate passively, without the need for direct network access. Detection and alerting is performed via secure egress.

CMS Cloud Command Center

The CastNet SaaS Command Center leverages world-class cloud infrastructure to deliver high availability and ironclad data protection.
 
  • Multi-user, Multi-Tenant: The Command Center allows for granting access to users in their respective organizations with strict controls around Identity and Access Management (IAM).
  • Tiered Hierarchy: organizations can be tiered by Organization, Site, Unit, and Zone, and user access can be restricted at any level. This allows owners to grant a property manager access to a specific site, for example.
  • Data Encryption: Your data is encrypted at rest using AES-256 and in transit utilizing TLS 1.3 encryption protocols.
  • Database Protections: All database connections are secured and row-level protection ensures access is properly restricted by organization, role, and user. 
  • Modern Cloud Infrastructure: Our cloud architecture is hosted on an enterprise cloud computing environment (CCE) and leverages cloud-native backup and recovery capabilities.
  • Infrastructure Isolation: Our cloud architecture utilizes strict logical separation, network firewalls, and continuous monitoring.
  • Access Control: We mandate Multi-Factor Authentication (MFA) for all administrative and user accounts.
  • Role-Based Access (RBAC): Administrators can provision granular permissions, ensuring users only interact with the specific hardware and data required for their roles.

Compliance & Governance

CastNet continuously aligns its operations with rigorous global security frameworks to guarantee verifiable protection.
 
  • Operational Maturity: We leverage proven practices found in the Entrepreneurial Operating System (EOS) business management framework.
  • Center for Internet Security (CIS): We align to the CIS Security Controls as our baseline framework for cybersecurity.
  • SOC 2 Type II (pending): We are preparing for independent third-party audits to verify that our security controls meet stringent trust services criteria.
  • Hardware Certifications: Our hardware components fully comply with FCC, CE, and relevant regional regulatory safety and electronic standards.
  • Data Privacy: CastNet strictly adheres to global privacy laws, including GDPR and CCPA regulations regarding data storage, processing, and user privacy rights.

Legal

The following pages are provided:

Contacts

Security practitioners: please reach out to us at security@castnet.ai.

Privacy requests: please use privacy@castnet.ai.

For general inquiries: please reach out to us at our Contact Page.