Secure by design — no Wi-Fi, EU-based hosting, full encryption.

Data security should not be something you have to worry about. RoomAlyzer is a multi-tenant platform used by customers across many countries and industries, and it is built so that security is part of the design from the start: no one can reach data that is not theirs, and your organisation always knows exactly who has access to what. Here is how it works, and why it makes your own risk assessment simpler.

25 years of building secure solutions online

Security is not new to us. IoT Fabrikken's solutions are built by people with more than 25 years of experience in secure online systems: from online payment solutions to data logging that safeguards food safety. That foundation gives us deep, practical knowledge of how data is transported and stored securely, and we keep our solutions up to date with the latest security standards. It is also why we hold ourselves to strict rules so that one thing is always true: you own your data, at all times, and no one else.

The IoT Fabrikken team

We never touch your Wi-Fi

We have two types of sensors: some have a built-in NB-IoT SIM card, and others send their data to a Cloud Connector, which passes it on to your app via its own SIM card. Either way, the data travels over a dedicated cellular network, never over your Wi-Fi. That means your measurements move completely separately from anything sensitive or confidential on your own network, and you avoid giving an outside system any access to your IT environment.

End-to-end encryption and EU-based hosting

All data is protected with full end-to-end encryption (AES-128), and everything is stored in the cloud with 100% EU-based hosting. You keep full ownership of your data, and you always know where it is kept. Beyond this, we apply standard production hardening: encrypted traffic (HTTPS/HSTS), protection against brute-force login attempts, and no credentials ever exposed in the browser.

Login you can trust, with optional two-factor

Every user signs in through Firebase Authentication, Google's enterprise-grade identity platform. RoomAlyzer never stores your passwords itself: sign-in, password resets, and account recovery are all handled by Firebase. For organisations that want an extra layer of assurance, two-factor authentication (the same six-digit code standard used by banks) is available, and you can make it mandatory for everyone in your organisation from the security settings.

Two-factor authentication settings in RoomAlyzer

The right access for each role

Not everyone needs the same access, so RoomAlyzer uses clear, role-based permissions:

RoleAccess levelDescription
Viewer
Read only

Can see data but not change it.

Manager
Operational

Have broad operational access.

Administrators
Full control

Can manage users and security settings, within their own organisation only.

Maximum security through server-side validation: Every permission is checked on the server with each request. Hiding a button in the interface is never enough on its own; the server independently confirms that you are allowed to do something before any data is shown or changed.

Access down to the single location

Within your organisation, access can be narrowed further. A user can be limited to specific buildings or rooms, so they only see the sensors, dashboards, and alerts they are meant to. It makes it simple to give a facilities team access to their own wing without exposing the rest of the building, or to give an external contractor a read-only view of a single floor: enforced both in the interface and on the server.

User limited to selected buildings and rooms in RoomAlyzer

Your data stays yours: strict tenant isolation

All customers share the same platform, but their data is completely separate. Every query is tied to your own organisation, resolved from verified server-side credentials, never from anything the browser could change. The same applies to integrations: an API key is permanently bound to one organisation and cannot reach another's data, even if a different ID is passed in the request.

A full audit trail

Every change to access is recorded. When a user is added or removed, a role is changed, or an account is created or deleted, an entry is written that cannot be altered: with who did it, to whom, what changed, and when. Administrators can review the full access history for any user, which makes internal compliance straightforward and answers the question everyone eventually asks: who had access to what, and when did that change?

Reviewing access history for compliance

Simpler GDPR and NIS2 assessment

Because RoomAlyzer records only technical measurement data (with no personally identifiable information) and combines that with no Wi-Fi dependency, EU-based hosting, and full encryption, it makes your own GDPR and NIS2 assessment considerably simpler. You get robust data protection and a clear, defensible setup, without the usual complexity.

See the platform with your own buildings

Book a short demo, or talk to sales about dashboards, reports, security and API access for your sites.