This is an archived version of this document, published 2026-09-10. The current version is at readybit.com/security.
READYBIT SECURITY DOCUMENTATION
Last updated September 10, 2026. Posted at readybit.com/security.
This page describes the administrative, physical and technical safeguards Readybit Inc. (“Readybit”) maintains to protect the security, confidentiality and integrity of Customer Data in the Readybit monitoring platform. It is the “Security Documentation” referred to in Readybit’s Reseller Agreement, Service Agreement, Order Forms and Terms of Use, and it matches Annex II of the Readybit Data Processing Addendum at readybit.com/dpa. Readybit is a small company, and this page describes what Readybit actually does today. Readybit updates it as its practices change and keeps the “Last updated” date current.
1. What the platform is
Readybit supplies connected monitoring hardware and a hosted dashboard. Readybit’s IQ-1 monitor mounts on an industrial container and reports fill level, temperature, orientation and the container’s location. Readybit’s connected gateway reads sensors on a customer’s equipment, such as fluid level and pump status, and reports them the same way. In both cases the device sends telemetry to Readybit’s cloud platform, where users view it and receive alerts. Readybit devices monitor and report only. They do not control the equipment or containers they are attached to, including any pump, dosing or safety function, and the equipment operates the same with the device unpowered or disconnected. Readybit’s Acceptable Use Policy, at readybit.com/terms, prohibits use of the platform in situations where a service interruption could result in personal injury or death unless the customer has fail-safe alternatives in place.
2. Data the platform is designed for
The platform is designed to hold three kinds of data:
- Equipment telemetry (“Sensor Data”): fill level or fluid level, temperature, orientation, pump status, usage, cycle counts, the location of monitored containers or equipment, device status, diagnostics and device identifiers. This is data about equipment and containers, not about people. Where a customer associates a mobile container with a named driver or vehicle so that its location history can reasonably be linked to that person, Readybit treats that location data as personal data under the Data Processing Addendum.
- Site and contact information: location names and addresses, on-site contact names and contact details, names of drivers, technicians and other personnel entered by users in connection with sites, routes, deliveries or alerts, notes entered by users, and photographs of monitored containers or equipment that users upload.
- User account details: name, business email address, business or mobile phone number (including a number supplied to receive alerts by text message), role, organization, login credentials (passwords are stored only in hashed form), sign-in records, and alert preferences.
The platform is not designed for, and customers must not submit, payment card data, protected health information, government identification numbers, precise personal geolocation, or other sensitive or regulated categories of data. Readybit’s agreements exclude those categories unless an Order Form expressly provides for them.
3. Hosting and physical security
The platform runs on infrastructure operated by DigitalOcean, LLC in the United States. Readybit does not operate its own data centers. Physical security of the hosting provider’s data centers, including access control, environmental protection and hardware disposal, is the responsibility of the hosting provider under its own certifications and controls. Customer Data is hosted and processed in the United States.
4. Encryption
Connections between users’ browsers and the dashboard, between Readybit devices and the platform, and between the platform and its sub-processors are encrypted in transit using TLS. TLS is terminated inside Readybit’s production environment; no third-party content delivery network or proxy sits in front of the dashboard. Customer Data is stored in managed database, block storage and object storage services that encrypt data at rest, and database backups are encrypted.
5. How devices connect and authenticate
Each Readybit device connects to the platform over cellular, Ethernet or Wi-Fi, depending on the model, and authenticates with credentials unique to that device, issued when the device is provisioned. Devices send telemetry to the platform. The platform does not accept unsolicited inbound connections from the public internet to devices. A device whose credentials are compromised can be deactivated on the platform without affecting other devices.
6. Access control
Access to production systems and to Customer Data is limited to the Readybit personnel who need it to operate and support the platform. Each person uses a unique account, and multi-factor authentication is enforced on the hosting console, source code repositories and Readybit’s email and identity provider. Access is reviewed when roles change and removed promptly when no longer needed. Within the platform, role-based access controls limit each user to the organizations, sites and devices they are authorized to see; for example, a reseller sees the locations in its program, a distributor sees its own customers, and a customer sees its own sites.
7. Network and application security
Production systems run on a private network with only the public endpoints needed for the dashboard, API and device connections exposed through a load balancer. Secrets and credentials are kept out of source code and managed through the hosting platform. Staging and production environments are separate. Code changes are tracked in version control and reviewed before release.
8. Logging and monitoring
Readybit logs authentication events, administrative actions and application errors, retains application logs for 30 days, and monitors for service errors and unusual activity.
9. Backups and resilience
The production database is backed up daily, with point-in-time recovery available across a rolling seven-day window, in the same hosting region. Readybit also keeps an independent record of device telemetry from which sensor data has been recovered in production. Because Readybit devices monitor rather than control equipment, a platform outage delays alerts and dashboard updates but does not affect the operation of the customer’s equipment.
10. Vulnerability and patch management
Readybit updates operating systems, container images and software dependencies as part of its regular release process, reviews dependency advisories, and prioritizes security fixes ahead of other work. Device firmware updates are delivered over the air to devices with an active subscription. Readybit does not currently commission third-party penetration tests and does not hold SOC 2, ISO 27001 or similar certifications, and does not represent that it does. Readybit will respond to reasonable security questionnaires from customers as described in the Data Processing Addendum.
11. Personnel
Everyone with access to Customer Data, including contractors, is bound by written confidentiality obligations.
12. Incident response and customer notification
Readybit investigates suspected security incidents, contains them, and preserves relevant records. Readybit will notify affected customers of any unauthorized access to or disclosure of their Customer Data without undue delay, and in any event within 72 hours after confirming it, by email to the administrator contact on the customer’s account. The notice will describe what happened, what data and how many records were affected as far as is known, what Readybit has done and plans to do, and a point of contact, and Readybit will provide the information customers and their channel partners reasonably need for their own notification obligations.
13. Retention and deletion
Customer Data is retained for the term of the customer’s agreement. For 30 days after termination Readybit makes Customer Data available for export, after which it is deleted from production systems within a commercially reasonable time and from backups as the backup cycle overwrites them, except where retention is required by law and except for records of each user’s acceptance of the Terms of Use, which are retained as evidence of contract formation. Sensor Data, de-identified telemetry and aggregate statistics that do not identify a customer or any person may be retained as provided in the customer’s agreement.
14. Sub-processors
The following providers process Customer Data on Readybit’s behalf. This list is the same as Annex III of the Data Processing Addendum. Readybit updates it here at least 15 days before adding a new provider and notifies customer administrators by email.
| Provider | Purpose | Location |
|---|---|---|
| DigitalOcean, LLC | Cloud hosting, managed database, storage and backups | United States |
| Okta, Inc. (Auth0) | User identity, authentication and sign-in for the dashboard | United States |
| Twilio Inc. (SendGrid) | Delivery of account, alert, invitation and report emails, and text message alerts where enabled | United States |
| Google LLC | Business email and customer communications, including support correspondence and service notices | United States |
The following providers support the platform but do not receive Customer Data that identifies a person in the ordinary course. The United States Census Bureau, the OpenStreetMap Foundation, Geocodio and Google LLC receive site street addresses, without contact details, to convert them to map coordinates. Google LLC (web fonts), the OpenStreetMap Foundation (map tiles) and jsDelivr (map assets) serve dashboard content that a user’s browser loads directly, and so receive the user’s IP address and browser information in the ordinary course of serving that content. Depending on how a user signs in, the user’s profile image may be loaded by the browser from Automattic (Gravatar) or Google. SitePartners (BlackBean Marketing), Readybit’s website agency in Canada, operates the readybit.com marketing website and its contact forms; support requests are handled by email to support@readybit.com and not through the website. They are listed for transparency.
15. Reporting a security concern
Report suspected vulnerabilities or security incidents to security@readybit.com. Readybit acknowledges reports within two business days and asks reporters to allow a reasonable time to fix a confirmed issue before disclosing it publicly.
16. Questions
Questions about this page or about Readybit’s handling of Customer Data can be sent to legal@readybit.com.