Security

Securing your IoT Edge devices

Balena ensures robust IoT security for your edge devices, protecting your fleet, data, and operations. Our secure platform supports reliable IoT fleet management and compliance with modern security standards.
Balena Trust Center

Explore our Trust Center to find detailed information about IoT security best practices, industry certifications, and how we keep your data safe.

Visit our Trust Center
Our Whitepaper

Learn about balena’s approach to IoT security in our whitepaper. Discover how we implement secure device management, data encryption, and compliance measures.

Download our Whitepaper

Why Trust balena with Your Next Project?

OTA Updates for Enhanced Security

Safeguarding security with reliable, verifiable updates, providing consistent application and kernel updates to keep fleets protected from potential attacks.

Compliance and Lifecycle Support

Ensuring IoT compliance with regular security updates and a secure development lifecycle, aligning with ISO 27001, CRA, and more from design to deployment.

Trust Center
Focus on Secure Fleets

Providing fleet security with Secure Boot, Full Disk Encryption, and Cloudlink for secure remote access, enabling trusted software execution and protected device communication.

User Access Management

Offering secure authentication methods, including credential-based login, OpenID Connect (e.g. GitHub, Google), 2FA, TOTP, and SAML-based Single Sign-On for enterprises.

Single Sign-On docs
Support Access with Customer Consent

Our support accesses devices only with customer authorization. Customers can disable access by removing the balena SSH key, ensuring full control over device access.

Find out about Support
Building Secure Images

Our builders ensure security with GPG/SHA256 base image checks, SSH-encrypted code transfers, and tightly controlled Docker registry storage for container images.

balena Base Image docs
Security Acknowledgments
At Balena, we welcome collaboration with external security researchers who discover vulnerabilities in our platform. We encourage researchers to responsibly introduce themselves and work with us to address issues. Please contact us at security@balena.io to report potential vulnerabilities, or for further information about our responsible security disclosure process.    
Last Updated: June 14, 2024

Name

Affiliation

Contribution

Disclosure Date

Resolution Date

Marco Jansen of Lorkeers

ThreatLabs

Marco reported a vulnerability in the 2FA recovery key management. We have implemented a mitigations.

April 22, 2024

June 14, 2024

Marco Jansen of Lorkeers

ThreatLabs

Marco reported a vulnerable gap in the 2FA setup. We have implemented a mitigation.

May 22, 2024

May 30, 2024

More on security at balena
Loading latest security related articles from our blog...

Still got questions?

Chat with our customer success team.

Contact Us