Skip to main content

The Ubicquia Security Program: Certifications, Encryption, and Vulnerability Management

How Ubicquia protects critical infrastructure with ISO 27001, SOC 2 Type 2, NIST 800-171, CTIA IoT certification, and continuous third-party vulnerability testing.

Ubicquia operates an audited, continuously improving information security program covering every product, service, and internal system. The program is built on ISO 27001 certification (audited) and SOC 2 Type 2 attestation (audited), and aligned to NIST 800-171, NIST CSF, PCI SAQ-C, CMMC level 1, and CTIA IoT device certification standards.

This isn't a certifications-only exercise. Ubicquia's Information Security Management System (ISMS) governs encryption, data segregation, secure software development, incident response, vulnerability management, and supply-chain risk — all validated through recurring third-party audits and independent penetration testing.

Certifications and standards

ISO 27001 / 27002 — AuditedFull Information Security Management System (ISMS) certification with recurring external audits. The baseline standard for enterprise security posture.

SOC 2 Type 2 — AuditedAttests to operational effectiveness of security controls over a sustained period. Standard for cloud infrastructure handling utility and municipal data.

NIST 800-171 & NIST CSFAligned to the federal frameworks used for controlled unclassified information (CUI) and cybersecurity risk management across critical infrastructure sectors.

CTIA IoT Device CertificationUbiCell certified under CTIA IoT security level 1 v1.2.3. CMMC level 1 performed through SPRS. PCI SAQ-C compliant for cardholder data segments where applicable.

Encryption and communication security

Every connection between Ubicquia IoT devices and cloud services uses TLS 1.2 or higher for transport, with encryption implementing the highest recommended NIST Federal Information Processing Standards (FIPS). Sensitive data at rest — on disk or backup media — is encrypted with AES-256.

Devices communicate over cellular LTE, segmented within the carrier network via an Access Point Name (APN) and delivered to AWS via VPN. This isolates Ubicquia telemetry from public internet exposure. The Trust M Security controller manages MQTTS and HTTPS certificates on-device, protecting the cryptographic identity of every deployed unit.

Data protection and customer segregation

Customer data lives in AWS RDS with encryption at rest, and is logically segregated per customer — no shared tables across accounts. Access is controlled through the UbiVu asset management platform's role-based access control (RBAC), so operational data reaches only the personnel authorized to see it.

Ubicquia generally does not collect personally identifiable information (PII). Data collection is limited to what's operationally required to deliver the service — a design choice that reduces regulatory exposure and privacy risk for customers and their end users.

Vulnerability management and incident response

The security program continuously monitors for new threats using automated scanning, internal security audits, and periodic external penetration testing. Identified vulnerabilities are logged, prioritized, assigned to an owner, and tracked through remediation. Incident response follows a documented process — pre-designated ISIRT (Integrated Security Incident Response Team) stakeholders, root cause analysis for every incident, and remediation lessons folded back into the ISMS.

Vendors and third parties are evaluated during onboarding for cybersecurity posture and re-reviewed at contract renewal or annually based on engagement risk. All vendors must comply with Ubicquia's cybersecurity commitments as a condition of engagement.

Download the Ubicquia Security Program white paper

Full detail on certifications, encryption, data protection, vulnerability management, and supply-chain risk for enterprise and government procurement teams.

Download PDF

Related insights

See all insights