Features · Security
Security and data protection that stand up to real-world demands
Hosting in Germany, encrypted transmission, role model, and audit log form the framework for GDPR-compliant data management in daily operations.
Kibi Scada doesn’t just protect data—it also safeguards responsibilities, documentation, and access. Hosting in Germany, encrypted data paths, role-based models, and audit logs provide the technical and organizational framework for this.
- Germany-based hosting with no data transfer to third countries
- AES-256, TLS 1.3, and encrypted device communication
- Roles, audit logs, and 2FA as part of platform operations
Auf einen Blick
Security is part of our product operations—not just a promise.
Encryption, permissions, audit logs, and data protection documentation work together seamlessly. Only then does security go from promise to a robust operational standard.
Typische Bausteine
Arbeitsweise
From access protection to audit-proof documentation
Three layers that belong together: who can access data, how data is protected, and how security-relevant actions can be traced later.
Control access securely
Users, roles, and locations are organized so that each person only sees the data and functions they actually need. This reduces risk and increases traceability.
Securely transmit and store data
From the sensor through the gateway and API to data storage, the entire path remains encrypted. This means security isn’t just a data center feature—it’s embedded in every step of the data journey.
Log all actions in an audit-proof manner
Changes, access, and security-relevant actions are recorded in an audit-proof manner. This ensures that incidents, approvals, and responsibilities can be reliably traced even in retrospect.
Im Detail
What security and data protection features need to deliver in this environment
Regulated businesses need more than encrypted transmission. What matters are clear roles, traceable changes, data storage in Germany, and a GDPR framework that remains practical in everyday operations.
Encryption
Security starts at the device and doesn’t stop at the browser.
Kibi Scada treats encryption as a continuous path: from sensor communication through gateways and VPN to API, web access, and backup.
- TLS 1.3 for web and API access
- Encrypted device communication via secured transport channels
- AES-256 for sensitive data and backups
- Traceable transport paths from device to cloud
Roles & Audit Log
Access and responsibility remain traceable.
Granular roles, location-based permissions, and audit logs ensure that sensitive data isn’t left exposed—and that changes remain traceable later. They keep sensitive data secure, while ensuring all modifications stay fully documented.
- Predefined and custom role models
- Location- and function-based access restrictions
- 2FA for critical accounts and administrative use
- Audit log for configurations, access, and changes
GDPR & Operations
Privacy is built into the platform’s framework.
Data center location, subprocessors, data processing agreements, and organizational measures aren’t just appendices—they’re essential for reliable operations in regulated environments.
- Hosting exclusively in German data centers
- Data Processing Agreement (DPA) and documented Technical and Organizational Measures (TOMs) for customer processes
- Prepared implementation of deletion, access, and data portability requests
- No unnecessary dependency on non-European data routes
Einsatzfelder
Where security and data protection become especially critical to compliance
The more locations, responsible parties, and documentation-required processes come together, the more crucial a security framework becomes—one that doesn’t just look good on paper but holds up under scrutiny.
Hospitals
Distributed kitchen, technical, and hygiene teams need a platform that neatly consolidates alert pathways, documentation, and location data.
Large-scale kitchens
High documentation requirements, numerous devices, and tight operational windows make seamless transparency on the platform especially valuable.
Catering
Mobile processes, multiple output points, and shifting teams benefit from a central system for monitoring, alerts, and reporting.
Service Partners
Tenants, technical responsibilities, and documented measures can be consistently managed on a single platform.
FAQ
Frequently Asked Questions About Security & Data Protection
Where is Kibi Scada data stored?
All data is processed and stored exclusively in German data centers operated by Hetzner. These data centers are ISO 27001 certified. No data is transferred to countries outside the EU. This ensures we meet the strictest GDPR requirements and guarantee full data sovereignty for our customers.
Is Kibi Scada GDPR-compliant?
Yes, Kibi Scada is fully GDPR-compliant. We provide a Data Processing Agreement (DPA) in accordance with Art. 28 GDPR, documented technical and organizational measures (TOMs), and support you in fulfilling your documentation obligations. All subprocessors are located within the EU.
How is data transmission between the device and the cloud encrypted?
IoT devices communicate with the Kibi Scada Cloud via encrypted VPN connections (OpenVPN with AES-256-GCM). LoRaWAN data is double-encrypted at both network and application levels. All web access and API connections use TLS 1.3 with Perfect Forward Secrecy.
How is personal data protected?
Personal data such as usernames, email addresses, and contact details are stored encrypted field by field using AES-256. Access to this data is strictly regulated on a role-based basis. Deletion requests in accordance with Art. 17 GDPR (Right to be Forgotten) can be implemented at any time.
How does role-based access control work?
Kibi Scada provides a role-based permission system with roles such as Administrator, Kitchen Management, Employees, and Service Partners. Each role defines which functions, devices, and data can be accessed within the tenant; Service Partners access only the locations assigned to them via separate customer tenants. All permission changes are logged.
Are there audit logs, and who has access to them?
Yes, Kibi Scada logs all security-relevant actions in an immutable audit log: logins, configuration changes, data exports, API access, and permission changes. The audit logs are only accessible to administrators and are retained for at least 12 months.
How are backups created and how secure are they?
Backups are created automatically and encrypted (AES-256). The backup rotation follows the 7-4-3 scheme: 7 daily, 4 weekly, and 3 monthly backups. Backups are stored at a separate location (geo-redundant), ensuring no data is lost even in the event of a data center outage.
Does Kibi Scada offer two-factor authentication?
Yes, two-factor authentication (2FA) can be enabled for all user accounts. Kibi Scada supports TOTP-based authenticator apps (Google Authenticator, Microsoft Authenticator, Authy) as well as FIDO2/WebAuthn security keys like YubiKey. For administrators, 2FA is mandatory.
Let's walk through the security architecture and GDPR framework in detail?
We show how Kibi Scada secures access, protects data paths, and which organizational proofs you can directly use for your environment.
Persönlicher Ansprechpartner
Christofer Wesseling
Founder & Managing Director · Weslink GmbH
We show Kibi Scada live on your equipment, advise you personally on integration and onboarding, and support the rollout in your operation.
Last updated: