null

Security and Compliance

Trust Center

How InduSol America handles data, credentials, and system access, across our website and store, our diagnostic products, and the platform integrations we build.

Last reviewed: October 2026

At a Glance

The Short Version

Different kinds of data follow different rules. These four points are the summary; each is expanded below.

Your personal data We collect and protect it. See our Privacy Policy.
Your plant network data Stays on hardware you own and control
Integration credentials Generated and held by you, never by us
Certifications ISO 9001 through our parent company
01

Three Different Kinds of Data

InduSol America, LLC is the North American arm of Indu-Sol GmbH. We sell industrial network diagnostic tools, monitoring devices, managed switches, and infrastructure components, and we provide training, consulting, and field service.

That means we handle three distinct kinds of data, and they are governed differently. Find the row that describes your situation, then read the matching section below.

Kind of data Examples Who holds it Covered by
Business and personal data Name, email, phone, shipping and billing address, order history, account login, support correspondence, newsletter subscription InduSol America and our service providers Privacy Policy and section 02 below
Website activity Cookies, analytics, advertising identifiers, pages viewed InduSol America and our analytics and advertising providers Cookie Policy and section 02 below
Plant network data Packet error rates, jitter, network load, device inventory, fault and alarm events You, on hardware you own Section 03 below

Important. We collect personal data from the people who buy from us and contact us, and we protect it. We do not collect or host the diagnostic data our products generate on your plant floor. Those are separate systems with no connection between them.

Requests for signed documentation, completed security questionnaires, or a data processing agreement are handled through the contact in section 06. Our Terms of Service and Disclaimer govern use of this website and the purchase of our products.

02

Business and Personal Data

This section covers you if you have bought from our store, filled in a form, subscribed to our newsletter, or contacted our team. Our Privacy Policy is the controlling document and describes your rights in full, including how to request access to or deletion of your data.

What we collect and why

Data Why we have it Where it lives
Contact and account details
Name, company, email, phone, addresses
Fulfilling orders, quoting, answering support requests, and arranging field service Our online store platform and our business systems
Order and transaction history Processing and shipping orders, warranty and RMA handling, and accounting Our online store platform and our business systems
Payment information Taking payment for an order Card details are handled by our payment processors. We do not store card numbers.
Support correspondence
Tickets, emails, uploaded files
Resolving your support case and improving our documentation Our business systems
Marketing preferences Sending the newsletter and product updates you asked for Our email marketing platform
Website activity Understanding how the site is used and measuring advertising Our analytics and advertising providers. See our Cookie Policy.

How we handle it

  • We do not sell personal data.
  • Access to business systems holding personal data is limited to employees who need it for their role.
  • Service providers process data on our behalf under their own agreements. A current list is available on request.
  • You can request access to, correction of, or deletion of your personal data. The Privacy Policy explains how, and which rights apply in your jurisdiction.

Files you send to support. When you send us a recording or report for analysis, through our file upload or by email, we treat it as confidential, use it only to resolve that support case, and retain it only as long as is necessary to provide you with support. This is the only route by which plant network data reaches us, and it only happens when you choose to send it.

03

Plant Network and Diagnostic Data

This section covers our products: INspektor® NT monitoring devices, handheld and portable testers, PROmesh managed switches, and the software used to configure and read them. Our devices observe industrial network traffic to report on network health. They read protocol and physical layer conditions, not process values or production recipes.

What our devices collect

Data type Example Collected
Network health metrics Packet error rate, jitter, retries, network load, signal quality Yes
Device and topology inventory Station address, device name, vendor ID, port mapping Yes
Event and alarm records Threshold breach, link loss, device breakdown or restart Yes
Process or production values Setpoints, recipes, product or batch data Not collected
Personal data Operator names, badge data, video Not collected

Where it lives

  • On the device. Diagnostic data is held locally on the device in a rolling buffer. Predefined communication anomalies and error logs are stored temporarily. Once the hardware ring buffer fills up, old data or snapshots are sequentially overwritten by newer events.
  • In your own systems. If you export data or enable an integration, it goes where you send it. From that point the receiving system's terms govern it.
  • Not on InduSol America systems. We operate no cloud service that receives, stores, or processes your network data. The only exception is a diagnostic file you choose to send to support, described in section 02.

Device behavior on your network

  • INspektor® NT diagnostic devices monitor passively. They read network traffic and do not participate in control communication or write to the process.
  • PROmesh managed switches are active network infrastructure: unlike the passive diagnostic devices above, they forward production traffic as part of normal operation. They are configured and administered by you, and we recommend deploying them in line with your own network segmentation and access-control policies.
  • Devices are configured by you. Default credentials must be changed at commissioning, and our documentation instructs installers to do so.
04

Integrations: Authentication and Authorization

This section applies only if you use one of our platform integrations. Integrations are optional, you enable them, and they send nothing until you configure them. If you are not using one, section 03 describes everything relevant to your products.

Available integrations

Platform Data sent Direction
MaintainX
CMMS
A work order built from a detected fault: fault type, affected device, and the asset it maps to Outbound only. Creates work orders and never reads data back from the platform.

How the connection works

The same model applies to every integration we build.

  • Who initiates it. You do, from inside your own platform account.
  • Who generates the credential. You do. You create an API key in your own account and enter it in the connector configuration on your own hardware.
  • Where the credential is stored. In a local configuration file on your machine. It is never transmitted to, held by, or visible to InduSol America.
  • Where the connector runs. On hardware you control, inside your environment. There is no InduSol-hosted service in the path.
  • Transport. Outbound HTTPS to the destination platform's public API. No inbound ports are opened on your plant network and no remote access to your site is required.

Permissions requested

We request the minimum scopes an integration needs to function and no others.

Platform Scope Why it is needed Access
MaintainX Work orders: create Open a work order when the diagnostic device detects a network fault Write

Revoking access

Revoke the API key in your own platform account. Access ends immediately and the connector stops sending. No action by InduSol America is required, and we cannot restore access on our own.

Access by InduSol America personnel

  • We hold no standing access to your platform accounts.
  • Any access during a support case is granted by you, scoped to that case, and removed when it closes.
05

Certifications and Compliance

The table below lists the frameworks and standards relevant to us and our status under each. Certifications held by our German parent company, Indu-Sol GmbH, are identified as such.

Framework Status Scope and notes
DIN EN ISO 9001:2015 Certified Held by our parent company, Indu-Sol GmbH (Schmölln, Germany). Scope: development and establishment of industrial networks and service.
Certificate No. 73 100 4160, issued by TÜV Hessen under DAkkS accreditation D-ZM-14137-01-00. Valid through 19 February 2028.
View certificate (PDF)
IEC 62443 Designed to Indu-Sol GmbH designs to IEC 62443 principles and supports customers in meeting the 62443-3-3 system requirements: identification and authentication, use control, system integrity, data confidentiality, restricted data flow, timely event response, and resource availability. Our products are not certified under 62443-4-1 or 62443-4-2.
CE and EMC conformity Compliant Declarations of conformity are available per product on request.
Industry standards bodies Member PROFIBUS & PROFINET International, EtherCAT Technology Group, Ethernet POWERLINK Standardization Group, Control System Integrators Association. Our products are built against published protocol specifications. See all memberships.
GDPR and CCPA Compliant Our Privacy Policy and Cookie Policy describe the personal data we collect, how we use it, and your rights over it.

Controls we operate

  • Our product architecture keeps plant network data out of InduSol America systems.
  • Platform credentials for integrations are generated and held by the customer, never by us.
  • Multi-factor authentication is required on email, CRM, store admin, and all necessary business systems.
  • Access to systems holding personal data is granted on a least privilege basis and reviewed regularly.
  • Accounts are removed immediately upon an employee's departure.
  • A documented firmware and software update process with published release notes.
  • A named security contact and a published vulnerability disclosure path.
  • Confidentiality obligations in employment and supplier agreements.
  • Cyber liability insurance. A certificate is available on request.

Note: SOC 2 and ISO/IEC 27001. We do not hold either. Both frameworks audit organizations that host and process customer data in their own systems. Our products and integrations run on customer-owned hardware, and we operate no cloud service that receives plant network data. Personal data from our website and store is handled by established platform providers under our Privacy Policy, and the controls we operate are listed above.

06

Reliability and Product Security

Our devices are built for continuous operation in production plants. Our products are engineered so that a failure in our software, or in a platform we connect to, does not affect the network being monitored.

Independence from connected platforms

  • Monitoring continues if your internet connection or a connected platform is unavailable. An integration outage delays reporting, not detection.
  • An integration failure cannot cause a network outage. The connector only reads from the device and posts outward.

Firmware and software updates

  • Releases are published on our downloads page with release notes.
  • Updates are applied by you. We do not push updates to devices on your network.
  • Security relevant fixes are identified as such in release notes and communicated to customers by email, when appropriate.

Recommended deployment practices

  • Change default device credentials at commissioning.
  • Place diagnostic devices in a segmented management network where possible.
  • Restrict a connector's outbound access to only the endpoints the integration requires.
  • Restrict file permissions on the connector configuration file, which holds the platform API key.

Support

07

Security Contact

We respond to vendor security reviews, questionnaires, and documentation requests directly. There is no gated portal and no NDA required to reach us.

Reporting a vulnerability. If you believe you have found a security vulnerability in an InduSol product, integration, or website, email security@indusolamerica.com. Please include the product and firmware version, a description of the issue, and steps to reproduce it.

We acknowledge reports within 24 hours, excluding weekends and holidays, and will keep you updated while we investigate. We ask that you give us reasonable time to issue a fix before public disclosure. We do not pursue legal action against researchers who report in good faith and do not access or modify customer data.

Security reports security@indusolamerica.com
Privacy and data requests info@indusolamerica.com

Available on request

  • Completed security questionnaire in your format
  • Data processing agreement
  • Current list of service providers that process personal data on our behalf
  • Certificate of cyber liability insurance
  • Product declarations of conformity

Related policies

  • Privacy Policy: what personal data we collect, how we use it, and your rights over it
  • Cookie Policy: cookies and tracking technologies used on this website
  • Terms of Service: the terms governing use of this website and purchases from our store
  • Disclaimer: limitations on the information published on this site