Secure by design — no Wi-Fi, EU-based hosting, full encryption.
Data security should not be something you have to worry about. RoomAlyzer is a multi-tenant platform used by customers across many countries and industries, and it is built so that security is part of the design from the start: no one can reach data that is not theirs, and your organisation always knows exactly who has access to what. Here is how it works, and why it makes your own risk assessment simpler.
25 years of building secure solutions online
Security is not new to us. IoT Fabrikken's solutions are built by people with more than 25 years of experience in secure online systems: from online payment solutions to data logging that safeguards food safety. That foundation gives us deep, practical knowledge of how data is transported and stored securely, and we keep our solutions up to date with the latest security standards. It is also why we hold ourselves to strict rules so that one thing is always true: you own your data, at all times, and no one else.

We never touch your Wi-Fi
We have two types of sensors: some have a built-in NB-IoT SIM card, and others send their data to a Cloud Connector, which passes it on to your app via its own SIM card. Either way, the data travels over a dedicated cellular network, never over your Wi-Fi. That means your measurements move completely separately from anything sensitive or confidential on your own network, and you avoid giving an outside system any access to your IT environment.
End-to-end encryption and EU-based hosting
All data is protected with full end-to-end encryption (AES-128), and everything is stored in the cloud with 100% EU-based hosting. You keep full ownership of your data, and you always know where it is kept. Beyond this, we apply standard production hardening: encrypted traffic (HTTPS/HSTS), protection against brute-force login attempts, and no credentials ever exposed in the browser.
Login you can trust, with optional two-factor
Every user signs in through Firebase Authentication, Google's enterprise-grade identity platform. RoomAlyzer never stores your passwords itself: sign-in, password resets, and account recovery are all handled by Firebase. For organisations that want an extra layer of assurance, two-factor authentication (the same six-digit code standard used by banks) is available, and you can make it mandatory for everyone in your organisation from the security settings.

The right access for each role
Not everyone needs the same access, so RoomAlyzer uses clear, role-based permissions:
| Role | Access level | Description |
|---|---|---|
Viewer | Read only | Can see data but not change it. |
Manager | Operational | Have broad operational access. |
Administrators | Full control | Can manage users and security settings, within their own organisation only. |
Maximum security through server-side validation: Every permission is checked on the server with each request. Hiding a button in the interface is never enough on its own; the server independently confirms that you are allowed to do something before any data is shown or changed.
Access down to the single location
Within your organisation, access can be narrowed further. A user can be limited to specific buildings or rooms, so they only see the sensors, dashboards, and alerts they are meant to. It makes it simple to give a facilities team access to their own wing without exposing the rest of the building, or to give an external contractor a read-only view of a single floor: enforced both in the interface and on the server.

Your data stays yours: strict tenant isolation
All customers share the same platform, but their data is completely separate. Every query is tied to your own organisation, resolved from verified server-side credentials, never from anything the browser could change. The same applies to integrations: an API key is permanently bound to one organisation and cannot reach another's data, even if a different ID is passed in the request.
A full audit trail
Every change to access is recorded. When a user is added or removed, a role is changed, or an account is created or deleted, an entry is written that cannot be altered: with who did it, to whom, what changed, and when. Administrators can review the full access history for any user, which makes internal compliance straightforward and answers the question everyone eventually asks: who had access to what, and when did that change?

Simpler GDPR and NIS2 assessment
Because RoomAlyzer records only technical measurement data (with no personally identifiable information) and combines that with no Wi-Fi dependency, EU-based hosting, and full encryption, it makes your own GDPR and NIS2 assessment considerably simpler. You get robust data protection and a clear, defensible setup, without the usual complexity.
Also in the platform
See the platform with your own buildings
Book a short demo, or talk to sales about dashboards, reports, security and API access for your sites.
