SismoSmartSeismic monitoring for buildings

Security

The data you never collect is the data you can't leak.

That's our basic rule. The only thing live right now is the website, but we're building the device side on the same rule.

Minimal data by default

The device sends only what's needed: motion, environment, operating status and the time of an event. We don't collect anything beyond that.

Consent before analytics

Web analytics load only after you consent. You can reset that choice at any time from the link in the footer.

Encrypted transport

The site runs on HTTPS with security headers. Device traffic is designed to be encrypted end to end.

No secrets reach the browser

Private keys and service tokens never appear in code that ships to the browser. They stay in server settings or in GitHub Secrets.

Vulnerability reporting

If you find a security issue on the site or in pre-launch materials, write to info@sismosmart.com. We're grateful to researchers who disclose responsibly.

Device security plan

Before the device ships we're committing to signed firmware, encrypted flash, two OTA partitions with automatic rollback, and a unique per-device key provisioned at the factory. Full security documentation goes live with the device.