Security is not the Enterprise tier.
Everybody gets all of it.

Put your own identity provider in front of your fleet on any paid plan, then get the detections a security team would otherwise have to build for itself: movement that does not add up, credentials going quiet, data leaving in shapes that do not match your normal traffic. The only Enterprise piece is streaming it into your own SIEM.

  • SSO on any paid plan
  • SCIM provisioning
  • MFA enforcement
  • Verified domains

Built around how accounts actually get taken.

Account takeover follows a small number of well-worn routes, and almost none of them look like an alarm going off. We watch all three shapes continuously, enriching each detection with fleet context, device access history and normal device access patterns that a generic security tool cannot see on its own.

Credentials nobody is watching

Keys and accounts that have gone quiet, and the ones that suddenly start working much harder than usual.

Movement that does not add up

Sign-ins from places, and at intervals, that do not fit how your organisation actually works.

Unusual flows once someone is inside

Access and data movement weighed against the shape of your own normal traffic, not a fixed ceiling.

The record covers the devices, not just the console.

Most platforms audit their own admin panel and stop there. The interesting question is not who changed a setting, it is who reached into a customer's hardware, and what they did when they got there.

Platform access

  • Sign-ins, failures and lockouts
  • MFA registration and removal
  • Users, groups and role changes
  • API keys, SSO and SCIM configuration

Device access and control

  • Terminal, port-forward and remote-file sessions opened
  • File transfers queued and started, with paths hashed
  • Device actions invoked, reboots and intents requested
  • Fleet jobs and remediation playbooks dispatched
  • Provisioning, claiming and wormhole configuration changes

High-risk support actions leave a record.

Sensitive account and access changes carried out by Dataplicity support are written to the same audit stream and raise a security detection. The record covers those high-risk actions without pretending every support interaction is one.

Somewhere you will actually see it.

In the product

Detections land in a security workspace where they can be reviewed, suppressed as accepted risk, and restored. Suppressions survive the rule firing again.

Webhook on first raise

A newly raised detection posts to your endpoint with the rule, title and severity, so it can open a ticket without anyone watching a dashboard.

The activity record, exportable

Filter the audit trail by user, action, source IP, device or time window, and export what you filtered as CSV for whoever asked.

Your SIEM, on Enterprise

Sentinel export streams the same events into Microsoft Sentinel on a normalised schema. This is the one part of security that is genuinely an Enterprise capability, because it exists for teams who already run a SOC.

Connect your first device.

Enter your email to get the install command. Security activity starts recording from the first sign-in.