Skip to content
CIAS Multisphera
Product

Security and compliance

What Multisphera protects, with which mechanisms, and what is always included or comes with CyberShield.

Principles

Security by design

Encrypted communications, a certificate for each installation, deny-by-default permissions, a retained event log. NIST/FIPS-approved cryptographic algorithms, such as AES-256-GCM, SHA-256, HKDF-SHA256 and ECDHE P-256.

On the site network

No cloud service is needed for surveillance. Events and logs stay in the installation.

Denied by default

Anyone who is not an administrator sees only what their role explicitly allows.

Encrypted in transit

HTTPS, WebSocket over TLS, CIAS04 over TLS 1.3 with mutual authentication.

Traceable

Event log kept online for 24 months, then in a verified archive.

Field channel

From terminal server to server, encrypted Coming soon

With IP-Doorway2 and the new firmware, each terminal server will have its own key and the channel to the server will be encrypted. IP-Doorway does not encrypt the channel.

Channel encryption is part of CyberShield.

Key exchange
ECDHE P-256, authenticated with a pre-shared key dedicated to each terminal server
Encryption
AES-256-GCM
Key derivation
HKDF-SHA256
Replays
protection against message replay
Allowed terminal servers
list of identifiers signed by CIAS, with protection against rollback to earlier versions
Access

Who gets in, and what they can do

  • Roles: Administrator, Operator, Installer, No access
  • Permissions: per module, menu and action, denied by default
  • Lockout: after repeated failed sign-in attempts
  • Automatic sign-out: after inactivity, with a configurable time
  • With CyberShield: mandatory two-factor authentication (app or e-mail), password expiry and history, single session, sign-in time windows
Event log

Events kept, not lost

  • 24 months online, then a local archive month by month
  • SHA-256 fingerprints and a chain of archive manifests
  • No deletion before the month is archived and read back
  • Restore of an archived month from the Event log page
  • With CyberShield an operations log with a hash chain and export to SIEM
Updates

Security patches for everyone

Even without a subscription

Security advisories and updates are available for every installation, with or without Sphera+.

Signed

Packages and advisories signed with Ed25519, identical online and offline.

Your data stays with you

The diagnostic package for support is pseudonymised and is sent only if an administrator authorises it.

Always included, or with CyberShield

The basic protections are always included. CyberShield adds the features required by stricter security policies. During the 90-day trial everything is active.

FeatureAlways includedWith CyberShield
Authentication, passwords stored with bcrypt, CSRF protection, HTTPSyesyes
Deny-by-default permissions, per roleyesyes
WebSocket over TLS and installation certificateyesyes
Lockout after failed attempts, sign-out after inactivityyesyes
Event log for 24 months and archiveyesyes
Security advisories and updatesyesyes
Mandatory two-factor authentication, password expiry and historynoyes
Operations log with a hash chain, export to SIEMnoyes
TLS certificates issued by the company CAnoyes
Time windows, single session, per-user permissionsnoyes
Channel encryption to IP-Doorway2 terminal servers (coming soon)noyes

Compliance

Multisphera is designed to support the security requirements of the NIS2 directive and the Cyber Resilience Act: controlled access, attempt lockout, encryption, activity logging, security updates for everyone. The details are in the product’s technical documentation.