Security First
Your IoT devices and data are protected with enterprise-grade security measures.
HTTPS + HSTS Encryption
All connections are encrypted with TLS 1.3 and HSTS headers. No plain HTTP allowed.
Token Authentication
Devices use secure tokens (registration tokens expire in 24 hours, permanent tokens are MAC-bound).
Session Management
Sessions auto-refresh every 60 minutes. Inactive sessions expire automatically.
Rate Limiting
20 requests/minute for anonymous users, 100 requests/minute for authenticated users.
Honeypot Protection
Automated detection and blocking of malicious probes. 20 failures = 24-hour ban.
Password Security
Passwords hashed with PBKDF2 + SHA-256 (260,000 iterations). No plain text storage.
Two-Factor Authentication
Optional TOTP (Google Authenticator) support for enhanced account security.
Daily Backups
Automated daily backups ensure your data is safe and recoverable.
Responsible Disclosure
Found a security issue? Please report it to security@oceanremote.net
We appreciate your help in keeping OceanRemote secure for everyone.