PalletVision Is Built to Survive Your IT Team's Security Review, Not Just Your Ops Team's Demo
Every dock technology pitch sounds airtight until IT gets a look at it. Then come the real questions: where the data actually lives, what happens the moment a device is compromised, who can reach what and how you would ever know if they shouldn't have. PalletVision was built by people who expected those questions, not people hoping nobody would ask. Here is the honest architecture, cloud, device, and network, so your security review can move as fast as the rest of the deal.
The short version: PalletVision separates every layer of the system, cloud, device, and network, so a problem in one layer cannot spread into another. PalletVision is SOC 1 certified, and our SOC 2 program, aligned to the AICPA Trust Services Criteria, is actively in audit and expected to be finalized in September 2026. Our practices also draw on the NIST Cybersecurity Framework (CSF) and CIS Controls.
Cloud Security
PalletVision's cloud infrastructure runs entirely on Google Cloud Platform. That means we inherit the physical and network security of Google's data centers, and production traffic is filtered through Google Cloud Armor before it ever reaches our application.
Encryption. Data in transit is protected with TLS 1.3, with TLS 1.2 supported as the minimum. Data at rest is encrypted with AES-256. All credentials are held in Google Secret Manager, not in application code or config files.
Customer data segregation. Each customer's data is logically separated, and the application enforces customer-scoped access on every single request. Your users and your devices only ever reach your organization's data, never anyone else's.
Access controls. Portal users are restricted to their own organization's data by role. Internal access to production systems is governed by mandatory multi-factor authentication, role-based cloud permissions, and scheduled access reviews, not standing admin access.
Data retention. Data on the device is retained for 30 days by default and can be configured to match your own retention policy.
Logging and governance. Every administrative action, authentication event, and data access event is logged. Our program is backed by signed security policies and ongoing security awareness training, including monthly phishing simulations for our own team.
Device & Fleet Security
Every PalletVision unit runs on NVIDIA Jetson Orin hardware and is managed as a sealed appliance, not a general-purpose computer your team has to patch, monitor, or maintain. Here is what that means in practice.
No internet exposure. Field units have no open inbound ports. Run an external scan against a site running PalletVision and you will find no exposed PalletVision services.
A private network, not the open internet. All fleet management runs over a self-hosted NetBird network built on WireGuard, the same protocol built directly into the Linux kernel and used by major VPN and networking providers worldwide. WireGuard's security has been formally verified by independent academic researchers, not just claimed by us or by NetBird.
Segmented and isolated by customer. Each customer's devices sit in their own segment of that private network, with no route between one customer's fleet and another. Within a segment, units cannot talk to each other, so a problem on one unit cannot spread across your warehouse or your wider fleet.
Locked-down devices. Units run Ubuntu LTS under a kiosk layer, with no desktop, no browser, and no file system access exposed. USB storage is rejected outright.
Signed software only. Every update package is signed with our company key and validated before it ships. A device refuses any update that is unsigned or altered in transit.
Patching that does not interrupt your shift. Security updates apply automatically in the background. Reboots are confined to an overnight window, and your team can defer that window if needed.
Credential management. Device credentials are unique per unit and rotated weekly through a self-hosted vault. Our own support staff never see or type a device credential.
Support access, logged and revocable. Remote support runs only over the private network, using per-person keys, with every session logged. If we ever need to cut off access fleet-wide, that is a single action, not a unit-by-unit cleanup.
Local processing. Image capture and inference happen on the device itself. Only inspection results, associated images, and metadata reach the cloud. Raw video never leaves your site.
Monitoring. We watch every device from a central dashboard. If a unit stops checking in, or its configuration changes unexpectedly, our team is alerted immediately, before it becomes your problem.
Why We Built It This Way
Most facilities are used to security questions being about a login screen. PalletVision put the same scrutiny on the parts of the system that live on your floor: the camera, the appliance, and the network it talks over. A system that touches your dock should not be the weakest link in your security posture. That is the standard we hold ourselves to.
Have More Questions?
This page covers the architecture. If your security or IT team needs additional information, please shoot us an email at solutions@palletvision.com, and we will get you what you need before you ever have to ask twice.
-1.png?width=400&height=100&name=PVHQ_Primary_Horizontal_Black-Blue_NoBox%20(1)-1.png)