Security architecture

The most comprehensively secured IoT network available to OEMs.

Each layer is independently robust. Together they mean traffic is secure from device to cloud — and a breach of one device can never be leveraged against another.

Security architecture

Security. It's in our DNA.

Any decent IoT system encrypts its data. But what about the network? The key infrastructure? Justworx secures every layer, independently.

  1. 1

    Private APN

    Cellular traffic runs on a private Access Point Name — it never touches the public internet at the carrier layer.

  2. 2

    SIM-to-Cloud VPN

    An encrypted VPN tunnel runs from the SIM on the device to the Justworx cloud, and only there.

  3. 3

    AES-256 Payloads

    Every data payload is encrypted with AES-256 at the device, before it is ever transmitted.

  4. 4

    Per-Device eFuse Keys

    A unique key is burned into each chip at manufacture — permanently unreadable, even with physical access.

Every device is cryptographically isolated at the hardware level. Breach one device and the key you recover is valid only for that device — no lateral movement is possible across the network. This is the kind of security intelligence agencies use. Now you will too.

Hardware identity

A key that can never be read.

Every node and gateway is assigned a unique cryptographic key at the point of manufacture. That key is written to an eFuse on the embedded processor and physically burned — permanently inaccessible through any mechanism, including physical access to the device.

A successful breach of one device's encryption yields a key that is valid only for that specific device. No lateral movement is possible across the network — each device is cryptographically isolated at the hardware level.

Defence in depth, by design.

Off the public internet

A private APN keeps cellular traffic on an isolated segment straight to the Justworx cloud — it never enters the public internet at the carrier layer.

Encrypted transport and payload

A SIM-to-cloud VPN encrypts the transport independently of the AES-256 encryption already applied to every payload at the device.

No shared secret

Because every device carries its own burned-in key, there is no master secret to steal and no way to pivot from one compromised device to the next.

Security you can build a business on.

The kind of security intelligence agencies use — available to any OEM, in a single module.

See the platform
Coming soon

Introducing Jax

What do you want to build?

Ask Jax, our AI product architect. Describe an idea — he maps it to the right Justworx hardware, platform and network, and helps you ship it.

Meet Jax