Security
SPEKTRA Edge OS is built for devices that run unattended, often in physically exposed locations. This section explains the security controls available to you and how to configure them.
Security at a glance
| Control | What it protects | You manage it via |
|---|---|---|
| Disk encryption | Data at rest on the configuration and data areas | Image creation; recovery tools on the device |
| TPM & device attestation | Device identity and integrity | Provisioning; device configuration |
| Secure Boot | Integrity of the boot chain | Device firmware (and certificate enrollment) |
| SSH access | Console and shell access | Dashboard / device configuration |
| User accounts | Local administrative access | Image creation; recovery tools |
| USB device control | Acceptance of USB peripherals | Dashboard / device configuration |
| Remote access | Operator access to devices | Platform; audit |
Defaults worth knowing
- A device ships without a usable default password; you set the administrator password yourself. See User accounts.
- The device accepts only outbound connections to the platform; no inbound platform connection is required. See Connectivity & ports.
- Disk encryption is optional and is chosen when you create an image.
In this section
- Disk encryption — encrypt data at rest, with automatic unlock and a recovery passphrase.
- TPM & device attestation — hardware-backed identity and integrity verification.
- Secure Boot — verify the boot chain in firmware.
- SSH access — control shell access, keys, and source restrictions.
- User accounts — the administrator account and password recovery.
- USB device control — allow only approved USB devices.
- Remote access — operator access through the platform and what is recorded.