Skip to content

WebAccess DMP Security Statement ​

Advantech Czech s.r.o.

WebAccess DMP is a robust remote management platform, providing seamless control and monitoring of your industrial networking devices. With a comprehensive range of features, from automated backups to extensive API support, the platform ensures your operations are efficient and secure.

WebAccess DMP Server and Communication Security ​

All communication between WebAccess DMP servers and external networks is encrypted in transit using the latest TLS 1.3 protocol to ensure data integrity and confidentiality. Authentication and authorization between the management server and devices are secured through a mutual Public Key Infrastructure (PKI), ensuring that only authorized devices and users can access the system.

WebAccess DMP is hosted on Amazon Web Services (AWS) data centers, including those located in Frankfurt, Germany. AWS provides a highly secure, compliant, and well-governed environment, ensuring the reliability and security of your critical operations. We also employ automated systems to perform regular backups of all databases, ensuring data resilience and rapid recovery in case of any incidents.

WebAccess DMP Account Security ​

We adhere to strict internal company procedures to secure user accounts, including storing salted, iteratively hashed passwords (PBKDF2-SHA512) and employing standardized user management practices. Multi-factor authentication (MFA) using time-based one-time passwords (TOTP) is available and can be enforced at the company level, adding an extra layer of security to user access, together with single-use recovery codes for account recovery.

Access control and tenant isolation. Access is governed by role-based access control with granular, per-company permissions, so users and service accounts receive only the privileges they need. Each tenant company's data is logically isolated from that of other tenants.

Defense against automated and credential-based attacks. WebAccess DMP applies layered controls to defend against credential stuffing, password brute-force, and other automated attacks:

  • Rate limiting and anti-automation at the edge. We apply rate-based rules to throttle and block abusive request volumes and distributed automated attempts before they reach application services. Requests exceeding these limits from a given source are blocked for the remainder of the window. Because throttling is applied per source IP rather than per user account, these limits stop automated abuse without ever locking out or disabling a legitimate user's account.
    • API requests: a maximum of 1,200 requests per source IP address per 2-minute window.
    • Login attempts: a maximum of 80 requests per source IP address per 5-minute window, applied specifically to the OAuth /token endpoint to defend against credential stuffing and password brute-force.
  • Protection against malicious account lockout. Failed password attempts do not trigger per-account lockout. Because rate limiting is applied at the firewall level, an attacker cannot deny service to a legitimate user by repeatedly submitting incorrect passwords against that user's account. Legitimate users therefore retain access even while an account is being targeted, and abusive sources are throttled or blocked independently.
  • Breached- and common-password screening. New and changed passwords are checked against a curated deny list of tens of thousands of the most common and previously breached passwords (derived from publicly maintained credential lists). Passwords that appear on the list are rejected, substantially reducing the success rate of credential-stuffing and dictionary attacks.
  • Configurable password policy. Password strength requirements — minimum length, character-composition rules, limits on similarity to previous passwords, and repeated-character limits — are configurable and enforced centrally at password creation and change time.
  • Uniform authentication responses. The sign-in flow returns a uniform "invalid login attempt" response regardless of whether the username exists, preventing account enumeration through the authentication endpoint.
  • Session hardening. Sessions use short-lived, sliding access tokens with limited-lifetime refresh tokens, and client sessions are terminated after repeated unauthorized responses. Expired authorization tokens are pruned automatically.

Audit logging. WebAccess DMP maintains comprehensive audit logging of user-initiated create, edit, and delete actions, providing an accountable record of changes made within the platform.

WebAccess DMP Security Development Process ​

Security is embedded in the development of WebAccess DMP, so that each update and feature release meets our security standards. Our approach encompasses the following key stages:

  1. Secure-coding awareness — Our development team maintains awareness of secure-coding practices, common vulnerability classes, and dependency management, and applies them throughout development.
  2. Security-driven design — Security requirements — such as encryption, input validation, and access-control rules — are considered during the design phase, so potential vulnerabilities are identified and addressed early.
  3. Review during development — Code is subject to peer review and automated static analysis before release, to identify and address issues during development rather than after deployment.
  4. Testing and feedback — We carry out focused internal security reviews and, when appropriate, engage independent specialists for targeted penetration testing. Insights from these reviews inform updates to our security guidelines and help us address identified issues promptly.

Continuous Compliance and Improvement ​

Advantech Czech s.r.o. is certified to ISO/IEC 27001:2022 under certificate 212893/B/0001/UK/En, issued on 12 June 2025 and valid until 11 June 2028. The NIS2 Compliance Statement dated 26 January 2026 confirms compliance with applicable NIS2 requirements, the lower-obligations regime for CZ-NACE Division 26 and registration of the regulated service in the NÚKIB Portal. This company-level status forms part of the governance framework for the service.

We operate a documented, risk-based process for managing vulnerabilities in third-party components, with remediation prioritized by severity, aligned with our ISO/IEC 27001 controls.

Secure Remote Management ​

WebAccess DMP is built with security at its core, ensuring that your remote management operations are not only efficient but also thoroughly protected against evolving cyber threats. Our commitment to continuous improvement and adherence to stringent security protocols guarantees that your critical infrastructure is in safe hands.