Security & Private Networking

A device in a car park, on a pallet or in a roadside cabinet is easy to reach and hard to watch. If its SIM can be pulled out and reused, or the device answers on the public internet, it becomes someone else's way in. Security here is applied in the network, so small devices do not have to carry it.

IMEI lockAnti-theft
IPsecSite-to-site
OpenVPNRemote access
No inboundPublic route
How it works

Traffic leaves only by the routes you choose

Devices connect into the network, and their traffic goes only where you send it: through an IPsec tunnel to your own network, or to engineers over OpenVPN. Devices can be kept with no route in from the public internet at all.

devicesIMEI-locked SIMsVoicePro IoT networkPrivate routingYour private networkIPSEC SITE-TO-SITE TUNNELEngineer laptopOPENVPN, STATIC PRIVATE IPPublic internetNO INBOUND ROUTE TO DEVICES
Built-in controls

Six controls, none of them on the device

IMEI lock

Each SIM is bound to the hardware you approve. A SIM taken out of a tracker or terminal will not work in another device.

Device isolation

Device profiles are separated at the SIM, so a compromised device cannot reach the rest of your fleet.

Off the public internet

Reach devices only through a private VPN or a private connection. Nothing needs to listen on a public address.

Encryption in the network

Connectors add TLS between the network and your cloud, so low-power devices send lean traffic that still arrives encrypted.

One global core

Every network connects into one core, with no roaming middlemen in the data path. Fewer hands on your traffic, and all of it inspectable.

Unusual behaviour shows up

Usage limits, cost alerts and per-device logs make a device that starts behaving differently visible quickly.

Private networking

OpenVPN or IPsec: which you need

OpenVPNIPsec
ForEngineers reaching devices for diagnostics, configuration and updatesLarge deployments sending data to a private network endpoint
How it worksEach user gets a static private VPN address and reaches their own SIMs by ping, SSH or HTTPA site-to-site tunnel between the network and your infrastructure, set up through the API
FirewallsPasses firewalls by looking like ordinary HTTPS trafficStandard IPsec to your gateway
Load on the deviceNone: encryption stays in the networkNone: encryption stays in the network
Worked example (illustrative)

A SIM is taken out of a parked tracker

The attempt

Someone removes the SIM from a tracker and puts it in a phone or a router to use its data.

The block

IMEI lock refuses the SIM in hardware it was not approved for, so it carries no data.

The response

The tracker stops reporting, which raises an alert, and you can deactivate the SIM from the portal in one click.

Design a private network for your fleet

Tell us how your devices need to reach your systems, and we will propose the VPN or IPsec setup and lock-down policy that fits.