Security and compliance
The basic protections are always included; CyberShield adds advanced features for stricter policies. What MultiSphera protects, and with which mechanisms.
CyberShield
Advanced security features, for stricter policies.
- Mandatory two-factor authentication, password expiry and history
- Operations log with a hash chain, to detect tampering
- Export to SIEM of security events
- Company CA certificates, time windows, single session, per-user permissions
- Encryption of the channel to the devices with the new generation of CIAS terminal servers (coming in 2027)
Always included, even without CyberShield: authentication, HTTPS, deny-by-default permissions, attempt lockout, event log for 24 months, security advisories and patches.
At expiry: 30 days of notice and 30 days of grace, then the advanced features are switched off. Surveillance continues.

Always included, or with CyberShield
The basic protections are always included. CyberShield adds the features required by stricter security policies. The 90-day trial licence includes everything.
| Feature | Always included | With CyberShield |
|---|---|---|
| Authentication, passwords stored with bcrypt, CSRF protection, HTTPS | yes | yes |
| Deny-by-default permissions, per role | yes | yes |
| WebSocket over TLS and installation certificate | yes | yes |
| Lockout after failed attempts, sign-out after inactivity | yes | yes |
| Event log for 24 months and archive | yes | yes |
| Security advisories and updates | yes | yes |
| Mandatory two-factor authentication, password expiry and history | no | yes |
| Operations log with a hash chain, export to SIEM | no | yes |
| TLS certificates issued by the company CA | no | yes |
| Time windows, single session, per-user permissions | no | yes |
| Encryption of the channel to the devices, with the new generation of CIAS terminal servers (coming in 2027) | no | yes |
Security by design
Encrypted communications, a certificate for each installation, deny-by-default permissions, a retained event log. NIST/FIPS-approved cryptographic algorithms, such as AES-256-GCM, SHA-256, HKDF-SHA256 and ECDHE P-256.
On the site network
No cloud service is needed for surveillance. Events and logs stay in the installation.
Denied by default
Anyone who is not an administrator sees only what their role explicitly allows.
Encrypted in transit
HTTPS, WebSocket over TLS, CIAS04 over TLS 1.3 with mutual authentication.
Traceable
Event log kept online for 24 months, then in a verified archive.
From terminal server to server, encrypted Coming in 2027
With the new generation of CIAS terminal servers and the new firmware, each terminal server will have its own key and the channel to the server will be encrypted. Previous-generation terminal servers do not encrypt the channel.
Channel encryption will be part of CyberShield.
- Key exchange
- ECDHE P-256, authenticated with a pre-shared key dedicated to each terminal server
- Encryption
- AES-256-GCM
- Key derivation
- HKDF-SHA256
- Replays
- protection against message replay
- Allowed terminal servers
- list of identifiers signed by CIAS, with protection against rollback to earlier versions
Designed for the site network
MultiSphera is designed for the site’s local network and must not be exposed to the Internet.
- Operator workstations: web interface over HTTPS and real-time updates over encrypted WebSocket (TLS).
- Remote access: through the company network or a VPN, never by exposing the server to the Internet.
- Terminal servers: CIAS terminal servers on the site network; with the new generation the encrypted channel is coming.
- Third-party systems: CIAS02, CIAS03 and CIAS04 plugins, the latter over TLS 1.3 with mutual authentication; WebAPI over HTTPS.
- CIAS portal: optional connection; activation and updates also with files.
Who gets in, and what they can do
- Roles: Administrator, Operator, Installer, No access
- Permissions: per module, menu and action, denied by default
- Lockout: after repeated failed sign-in attempts
- Automatic sign-out: after inactivity, with a configurable time
- With CyberShield: mandatory two-factor authentication (app or e-mail), password expiry and history, single session, sign-in time windows
Events kept, not lost
- 24 months online, then a local archive month by month
- SHA-256 fingerprints and a chain of archive manifests
- No deletion before the month is archived and read back
- Restore of an archived month from the Event log page
- With CyberShield an operations log with a hash chain and export to SIEM
Security patches for everyone
Even without a subscription
Security advisories and updates are available for every installation, with or without Sphera+.
Signed
Packages and advisories signed with Ed25519, identical online and offline.
Your data stays with you
The diagnostic package for support is pseudonymised and is sent only if an administrator authorises it.
Compliance
MultiSphera is designed to support the security requirements of the NIS2 directive and the Cyber Resilience Act: controlled access, attempt lockout, encryption, activity logging, security updates for everyone. The details are in the product’s technical documentation.