SECURITY AND STANDARDS

Security is a product lifecycle, not a feature

For a device that stays in the field for ten years, the real question is not “is there encryption” but “what happens when a vulnerability appears, and until when is it supported”.

SECURITY CONTROLS

Controls verified today

The topics below have been verified by the product team. Technical detail and related documents for each row are shared in the technical file.

Verified security controls and their scope.
Topic Status Scope
Device identity and commissioningVerifiedEvery device carries a unique identity number created once during production.
Mutual authenticationVerifiedThe device and the server authenticate each other on first connection.
Communication encryptionVerifiedEvery communication is encrypted with AES-128.
Key managementVerifiedEach device uses its own AES-128 key; keys are managed through İnodya's infrastructure.
Firmware integrityVerifiedThe firmware package is cryptographically signed and encrypted, and anti-rollback protection is active. Thanks to the dual-bank layout, an interrupted update leaves the device booting the previous version.
Command authorisationVerifiedValve commands can be issued by the utility or by an authorised customer; when the utility withdraws that permission, the customer can no longer issue commands. The command and its issuer are recorded on the IWS Platform.
Logging and audit trailVerifiedThe device records all of its actions in its own memory: approximately 12,000 hourly, 1,200 daily and 200 monthly records, plus 4,000 event records. Logs can be retrieved over NB-IoT or on site via BConnect.

This table reflects the product team's verification work. The encryption mode, key management detail and certification scope are shared per project together with the technical file.

SUPPORT POLICY

Product support policy

For a public buyer what matters is not the moment of purchase but the years that follow. The terms below are provided as a visible annex to the contract.

  • Support starts on the date the product is invoiced and first activated.
  • Hardware, spare parts and service support: 2 years from the date of sale.
  • Software and cybersecurity updates: 10 years from the date of sale.
  • Security updates are distributed remotely over OTA and, where needed, on site via BConnect by authorised personnel.
  • For a critical vulnerability: initial assessment or mitigation within 72 hours, permanent patch within 30 days at the latest.
  • Vulnerability disclosure channel: [email protected]
  • End of sale is announced at least 6 months in advance. Spare parts and hardware maintenance continue for 10 years afterwards, and software and security support for 10 years from end of life.

REGULATORY CONTEXT

Topics considered in Europe and Türkiye

The following is informational and does not constitute a declaration that the product conforms to these frameworks.

RED cybersecurity requirements

Cybersecurity requirements for internet-connected radio equipment have applied since 1 August 2025. EN 18031-1:2024 has been published as a harmonised standard, with restrictions.

Cyber Resilience Act

Regulation (EU) 2024/2847 requires secure design, vulnerability handling, security updates and disclosure of the support period. General application starts 11 December 2027; reporting obligations start 11 September 2026.

NIS2

Drinking water suppliers and distributors are listed among sectors of high criticality. This means supply chain security, incident management and update capability will be assessed more strictly.

KVKK / GDPR

Detailed consumption data can constitute personal data revealing household behaviour. Data minimisation, retention period, access rights, audit trail and notification must be part of the design.

ETSI EN 303 645

Provides a useful security baseline for consumer IoT devices. It is not on its own evidence of conformity for a municipal water meter; it is treated as a complementary reference.

DLMS/COSEM

Defines a standard data model between devices and head-end systems. It is not present in the current Orion NB-IoT release; the Water Smart Meter Generic Companion Profile target is on the roadmap.

This section is not a legal declaration of conformity. Review by a regulatory and conformity specialist is required before publication; applicable requirements vary by target country and project.

RELEASE STATUS

Security today and what comes next

Roadmap items are work not present in the current release. Preserving that distinction is critical for a buyer writing a technical specification.

Current release

The approach we can discuss today

Not a claim — the way of working that is applied.

  • Remote update capability: the ability to close a vulnerability is intended to be preserved through the product's life.
  • Rollouts run in stages, and the device stays operational if interrupted.
  • Commands and their results are reported traceably.

Technical detail and verification records for these items are shared in the technical file.

Planned next release

Security work on the roadmap

These items are not present in the current release and are not a declaration of conformity.

  • DLMS/COSEM data model and communication profile
  • Gap analysis for European target-market security requirements
  • Related conformity and interoperability test plan

The roadmap is not a binding delivery date or a declaration of current conformity. Final scope and timing are given in the product announcement.

A smart water meter installed in a meter chamber beneath a city street.

NEXT STEP

Start by measuring in your own network

Let us validate the coverage, data, battery and integration assumptions together in a limited pilot. We write the success criteria before the pilot begins.