> For the complete documentation index, see [llms.txt](https://captic-2.gitbook.io/docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://captic-2.gitbook.io/docs/overview/good-to-know/security/device-and-cloud-security.md).

# Device & Cloud Security

How the Captic device and cloud protect your data.

Security is built into every layer of the Captic platform, from the device on your line to the Captic cloud. We follow industry best practices and continuously update our security measures.

## Device security

### CE-certified components

We use CE-certified components for hardware quality and compliance, reducing the risk of malfunctions, hazards and non-compliance.

### Tamper protection

Devices have dedicated security chips that encrypt data at rest. If someone tries to take the device apart, the data becomes unreadable.

### Strong authentication

* Strong credentials (16+ characters) on every device
* Role-based access control (RBAC), following the least-privilege principle

## Cloud security

The Captic cloud runs on Microsoft Azure.

* **Encryption in transit:** all data is encrypted with TLS.
* **Encryption at rest:** data is stored in Azure Blob Storage with AES-256 encryption.
* **Role-based access control:** access to cloud resources is limited to authorised users, following the least-privilege principle.
* **Microsoft accounts:** all access is secured with Microsoft accounts (Azure AD), including multi-factor authentication and central auditing.

{% hint style="info" %}
Security questions? Contact <security@captic.com>.
{% endhint %}
