Security and compliance
What Multisphera protects, with which mechanisms, and what is always included or comes with CyberShield.
Security by design
Encrypted communications, a certificate for each installation, deny-by-default permissions, a retained event log. NIST/FIPS-approved cryptographic algorithms, such as AES-256-GCM, SHA-256, HKDF-SHA256 and ECDHE P-256.
On the site network
No cloud service is needed for surveillance. Events and logs stay in the installation.
Denied by default
Anyone who is not an administrator sees only what their role explicitly allows.
Encrypted in transit
HTTPS, WebSocket over TLS, CIAS04 over TLS 1.3 with mutual authentication.
Traceable
Event log kept online for 24 months, then in a verified archive.
From terminal server to server, encrypted Coming soon
With IP-Doorway2 and the new firmware, each terminal server will have its own key and the channel to the server will be encrypted. IP-Doorway does not encrypt the channel.
Channel encryption is part of CyberShield.
- Key exchange
- ECDHE P-256, authenticated with a pre-shared key dedicated to each terminal server
- Encryption
- AES-256-GCM
- Key derivation
- HKDF-SHA256
- Replays
- protection against message replay
- Allowed terminal servers
- list of identifiers signed by CIAS, with protection against rollback to earlier versions
Who gets in, and what they can do
- Roles: Administrator, Operator, Installer, No access
- Permissions: per module, menu and action, denied by default
- Lockout: after repeated failed sign-in attempts
- Automatic sign-out: after inactivity, with a configurable time
- With CyberShield: mandatory two-factor authentication (app or e-mail), password expiry and history, single session, sign-in time windows
Events kept, not lost
- 24 months online, then a local archive month by month
- SHA-256 fingerprints and a chain of archive manifests
- No deletion before the month is archived and read back
- Restore of an archived month from the Event log page
- With CyberShield an operations log with a hash chain and export to SIEM
Security patches for everyone
Even without a subscription
Security advisories and updates are available for every installation, with or without Sphera+.
Signed
Packages and advisories signed with Ed25519, identical online and offline.
Your data stays with you
The diagnostic package for support is pseudonymised and is sent only if an administrator authorises it.
Always included, or with CyberShield
The basic protections are always included. CyberShield adds the features required by stricter security policies. During the 90-day trial everything is active.
| Feature | Always included | With CyberShield |
|---|---|---|
| Authentication, passwords stored with bcrypt, CSRF protection, HTTPS | yes | yes |
| Deny-by-default permissions, per role | yes | yes |
| WebSocket over TLS and installation certificate | yes | yes |
| Lockout after failed attempts, sign-out after inactivity | yes | yes |
| Event log for 24 months and archive | yes | yes |
| Security advisories and updates | yes | yes |
| Mandatory two-factor authentication, password expiry and history | no | yes |
| Operations log with a hash chain, export to SIEM | no | yes |
| TLS certificates issued by the company CA | no | yes |
| Time windows, single session, per-user permissions | no | yes |
| Channel encryption to IP-Doorway2 terminal servers (coming soon) | no | yes |
Compliance
Multisphera is designed to support the security requirements of the NIS2 directive and the Cyber Resilience Act: controlled access, attempt lockout, encryption, activity logging, security updates for everyone. The details are in the product’s technical documentation.