Security and compliance
What you will have to show your systems team
In critical infrastructure the final technical call is not made by the person who needs the system, but by the person accountable for the network. This page is written for them.
Starting principle
Metrosafe was designed on the assumption that it will operate inside critical infrastructure and is therefore new attack surface for the operator. The default posture is restrictive: fewer permissions, less exposure, less retention, and everything logged.
- Everything encrypted, in transit and at rest. No exceptions for test environments.
- No access without a second factor.
- No permission granted by default: it is granted by role and by scope.
- No query against the history without leaving a trace.
- No data retained beyond what the operator’s policy defines.
Technical controls
| Area | Control |
|---|---|
| Encryption | TLS 1.2 or above in transit; encrypted disks at rest; key management and rotation |
| Identity | Mandatory two-factor authentication, password policy, optional SSO against the operator’s directory |
| Authorisation | Role-based access control (RBAC) scoped geographically and functionally |
| Network | Microsegmentation, environment segregation, filtering and load balancing with WAF |
| API | Per-credential rate limiting, scoped service credentials, protection against OWASP API risks |
| Traceability | Structured logging, audit trail of access and actions, defined retention |
| Development lifecycle | Continuous SAST and DAST in CI/CD, dependency scanning, controlled deployment channel |
| Operations | Telemetry, metrics and traces, SLO dashboard, alerting and backups with a recovery procedure |
Independent verification
The controls above are declared by the vendor. What makes them defensible before a committee is having them verified by someone who is not the vendor.
- Grey-box penetration testing of portal, API and infrastructure, performed by an independent external auditor.
- Technical and regulatory verification of controls against OWASP API good practice and against ENS and ISO 27001 controls, with documented evidence.
- Load and concurrency testing with declared operating limits and known degradation behaviour.
- Verified finding closure: the acceptance criterion is zero open critical findings.
Regulatory framework
Certifications and conformity
- ISO/IEC 27001 — information security management system
- ISO 9001 — quality management system
- UNE 166002 — R&D and innovation management system
- Conformity with the Spanish National Security Framework (ENS), using CCN-STIC guidance as the technical reference
NIS2 and CER
Directive (EU) 2022/2555 (NIS2) and Directive (EU) 2022/2557 (CER) raise cybersecurity and physical resilience requirements for essential entities, and transport is expressly within their scope. For an affected operator this translates into concrete obligations around risk management, incident reporting and supply chain oversight.
Metrosafe is built to fit inside that framework without friction: an audit trail of access and actions, reproducible evidence of what happened during an incident, documented technical controls, and a supplier able to provide its own evidence when the operator has to account for its supply chain.
It is worth being precise here: a tool does not “comply with NIS2” on its own. The entity complies, or does not. What Metrosafe does is avoid making that harder, and supply the evidence the operator needs to demonstrate it.
How worker data is handled
Locating a person means processing personal data, and in an employment context that comes with its own rules. In practice it is also the objection that blocks most deployments of this kind. It deserves a straight answer rather than a footnote.
- Legal basis and bounded purpose: the purpose is operational safety and emergency coordination, not performance monitoring. The two uses are not mixed.
- Prior information to the worker and their legal representatives, in line with article 90 of the Spanish LOPDGDD, which requires express, clear and unambiguous information about the use of geolocation systems.
- Minimisation: the system publishes zone and area, which is what operations need. Fine resolution exists for map matching, not for watching anyone.
- Time limitation: location is collected during the shift and at the configured rate, not permanently.
- Bounded, configurable retention, with automatic deletion once the operator’s defined period expires.
- Anonymisation available for analytics and planning uses, which do not need to know whose trajectory was whose.
- Access logging: every query against the history is traced, so it can be demonstrated who looked at what, and when.
A well-planned deployment is explained to the works council before it is explained to the control room. It is the most underestimated part of the project and the one that most often decides whether it goes ahead.
Service continuity
- Committed availability
- SLA ≥ 99.95 %
- Support
- 24 × 7 × 365
- Observability
- metrics, logs and traces with a customer-visible SLO dashboard
- Backup and recovery
- periodic backups with a tested restore procedure
- Verified scale
- ≥ 70 concurrent terminals under nominal use
The SLO dashboard is visible to the customer. A service level only the supplier can verify is not a commitment, it is a statement of intent.
Shall we send you the security pack?
Architecture, controls, audit scope and data handling. What your systems team needs in order to sign off, or not.
- +34 924 090 608
- [email protected]
- Campus Universitario, Avda. de la Investigación S/N, Edificio PCTEX, Oficina 2.1
06006 Badajoz