OC
OceanRemote
Low-code IoT platform

Security First

Your IoT devices and data are protected with enterprise-grade security measures.

🔒

HTTPS + HSTS Encryption

All connections are encrypted with TLS 1.3 and HSTS headers. No plain HTTP allowed.

🎫

Token Authentication

Devices use secure tokens (registration tokens expire in 24 hours, permanent tokens are MAC-bound).

Session Management

Sessions auto-refresh every 60 minutes. Inactive sessions expire automatically.

🚦

Rate Limiting

20 requests/minute for anonymous users, 100 requests/minute for authenticated users.

🍯

Honeypot Protection

Automated detection and blocking of malicious probes. 20 failures = 24-hour ban.

🔑

Password Security

Passwords hashed with PBKDF2 + SHA-256 (260,000 iterations). No plain text storage.

📱

Two-Factor Authentication

Optional TOTP (Google Authenticator) support for enhanced account security.

💾

Daily Backups

Automated daily backups ensure your data is safe and recoverable.

Responsible Disclosure

Found a security issue? Please report it to security@oceanremote.net

We appreciate your help in keeping OceanRemote secure for everyone.