Five questions our customers ask before they hand us their data, answered plainly by the person who reads the questionnaires.
Every pilot begins not with a sensor but with a document. Before we ever set a magnetic sensor on a spinning machine, a security questionnaire arrives, and it tends to arrive the way a raven arrives, uninvited, faintly ominous, and expecting a thorough answer. I read these for a living. After enough of them you notice that beneath the hundreds of rows and the tiered dropdown menus, customers are really asking the same handful of things, over and over, in the small hours before trust has been earned.
So I decided to answer them here, in daylight, for our customers and for the poor souls across the table who answer these questionnaires for a living. Everything below matches what we already put in writing, in our SMARTdiagnostics Security Overview and the policies that sit behind it.
1. Who can get into my data and how do you keep everyone else out?
This is the first question, always, and it is the correct one to be afraid of. Access to SMARTdiagnostics rests on a few controls that only mean anything when they work together. You sign in with an email and a password that we hold to real length and complexity requirements, and most larger customers bring their own identity provider through SAML 2.0 single sign-on, whether that is Entra, Okta, or Ping. Your multi-factor rules, your conditional access, your lockout policy, all of it follows the user in, because your identity provider governs the sign-in and we honor whatever it tells us.
Inside the platform, nobody sees everything. We map every user to one of four roles, corporate or location, admin or read-only, so a technician at one plant sees that plant and stays a polite stranger to the other fourteen. Provisioning is deliberately manual. Software can spin up an account in a heartbeat, yet it has no way of knowing that this particular person should see one site and nothing beyond it. That judgment wants someone who understands your org chart, so someone who understands it makes the call. When a person leaves, their access falls away in the application or through your IdP, quietly and at once. Behind the scenes we tie every account to a unique internal identifier, so each action traces back to one named person and nothing happens anonymously. Role-based access control and least-privilege sit under all of it, which is usually the first box a security team wants ticked.
2. Where does my data actually live and what keeps it safe there?
It lives in the cloud, on Amazon Web Services, inside the continental United States and nowhere else. It travels there through channels that do not open for anyone merely asking politely, encrypted in transit with TLS 1.2 or better. It stays encrypted once it arrives, at rest under AES-256 with elliptic-curve cryptography, in the dark, whether or not a soul is watching. Encryption runs by default in both directions, so there is no toggle for anyone to forget on a Friday afternoon. We also collect very little personal information to begin with, a name, an email, a phone number, and an IP address, only what the software needs to do its job. The restraint is deliberate, which means we are not sitting on much that an attacker would even want.
For customers who worry about the edge, and the wise ones do worry, we go a step further. Our sensors only listen, they never touch the machinery they watch, and they speak a proprietary wireless protocol, KCF’s own DARTwireless, kept well apart from your Wi-Fi. Where you want genuine separation, our cellular base stations carry their own LTE connection and stay virtually air-gapped from your corporate network, so our data collection never becomes a quiet hallway into your world. The whole arrangement has one stubborn goal, which is to hand you a rich picture of your machines while handing an intruder nothing at all. And no, pulling our traffic onto your own network so you can watch it does not make you safer. If your service allows it, take the cellular modem.
3. How do you keep watch and what happens on the bad night?
Walls only get you so far. The harder discipline is watching, and remembering exactly what you saw. On-call security engineers keep an eye on the environment around the clock, and our monitoring stack, GuardDuty and CloudTrail and Microsoft Sentinel among others, holds immutable logs that let us walk backward through events when something feels wrong, the way you find yourself rereading a single creak in the floorboards. A second rotation, software engineers this time, stands ready to bring the system back inside our defined recovery windows if anything ever falls over.
When something does go wrong, we have a written incident response plan and a standing commitment to tell you within twenty-four hours of discovering a breach that reaches your data. You would hear it from us, with what we know and what we are doing about it, instead of learning it later in some place you never wanted to hear it. We would sooner describe the bad night to you honestly than pretend the night never comes. We also keep a public vulnerability disclosure page (kcftech.com/vulnerability-disclosure-policy) and a live status page (kcfstatus.com), so our transparency is something you can check rather than take on faith. And for the record, we have not had that bad night, at least not since I have been here, which is a fair sign the controls are meeting intent.
4. What becomes of my data over time and can I get it back or get it gone?
The machine data we collect is non-identifying by design, not sensitive personal information, which already spares everyone a good deal of anxiety. What personal information we do hold, mostly the names and email addresses that let people sign in and get alerts, carries a defined end date, because keeping it forever runs against both our own policy and the GDPR and other applicable privacy laws.
If you ask us to erase your data, our policy hands us a fixed window to do it and to carry that request to anyone downstream who might be holding a copy. Accounts that lapse get a one-year grace period, after which the data expires and is removed for good, save for whatever the law obliges us to keep. And if you want to keep your data longer, three years or five or ten, you can pull it through our API with your own key and store it wherever you like, at your own cost. You should never feel that handing us your data was the same as losing sight of it.
5. How do I know you actually do any of this?
A fair question, and a faintly menacing one. Anyone can arrange reassuring words in a tidy row. I am doing it right now. What separates the words from the evidence is that ours is written down and audited. KCF holds ISO/IEC 27001:2022 certification and a SOC 2 report, both examined by outside auditors with no reason whatsoever to flatter us, and we sit for penetration tests every year. We watch our own controls continuously rather than tidying the house the week before company comes over. There is a reason the whole thing is built this way. KCF started in the defense world, where the security bar sits punishingly high, and we carried that bar straight into the industrial space without ever lowering it.
We stay honest even about our own flaws. KCF publishes its vulnerabilities as CVEs through MITRE, with my own name attached to the ones I find. So when your questionnaire lands on my desk, the answers arrive with the certificate and the report attached, and you are welcome to read every line. The reports themselves are available under a mutual NDA at trust.kcftech.com.
+ And what about AI, since everyone is asking now?
This question is newer, and it arrives more often each month, usually near the end of the document where the genuinely modern anxieties like to gather. The short version is deliberately dull. SMARTdiagnostics watches machines, and it does not feed your data into some model to be digested and half-remembered later. Our KCFchat assistant will happily pull up an instructional document and walk you through setting up a sensor, but it cannot and will not reach your machine-health data or your PII. Similarly, none of KCF’s equipment is designed for SCADA or machine control of any kind, so there is simply no risk of an AI controlling your machine.
Behind that sits a strict internal Generative AI Policy. It forbids putting customer data or personal information into AI tools, it bars anyone from using our systems to train third-party models, and it keeps AI in a purely advisory seat, never at the controls of a device or an account. Every insight an AI so much as touches gets human review before it goes anywhere near a decision, and we guard hard against the particular ghost that haunts these systems, the confident falsehood. We are strict about PII, so the policy is not left to good intentions. We train every employee on responsible AI use and back that training with real technical controls. If we ever build a feature that puts AI near your data, you hear about it first and you consent before it happens. I would rather already hold these answers than compose them in a hurry as the questions slide under the door.
One last thing
Security is built into the architecture, into who may sign in, into where the data sleeps, and into what we actually do at three in the morning when an alert refuses to behave like a false alarm. The questions above are the ones that matter most to the people who trust us, so they are the ones I lose the most sleep answering well.
If you have a question I did not answer here, send it my way. If you are wondering about it, someone else is wondering too, and it belongs in the next one of these.