navigate openesc close
Book a demo

Resources

Data sovereignty and Law 25 for municipal IoT.

A street lighting network produces operational data every night: which fixtures are on, how much energy each draws, where a fault is. Where that data is stored, who can reach it and how it travels matters to a Quebec municipality under Law 25, and to any public agency with a data residency rule.

Where is Dimonoff’s lighting data hosted?

Dimonoff | SCMS runs either in certified cloud hosting with data residency in Canada or on the customer’s own premises, and that choice is what lets a Quebec municipality answer Law 25’s questions about where its information is kept and how it is protected.

Groupe Vectanor, Dimonoff’s parent organization, has completed a SOC 2 Type II audit covering security, availability and confidentiality. Radio communications are encrypted with AES-128 (AES-256 available on Digi XBee PRO radios), platform users authenticate with OAuth 2.0 under role-based access control, each gateway carries its own passwords, certificates and keys, and access to the server API is protected by X.509 certificates.

Data sovereignty and Law 25 for municipal IoT.

  1. What Law 25 asks of a public body

    Quebec’s Law 25 modernized the rules on the protection of personal information for public bodies and enterprises: how information is collected, where it is kept, how it is protected, and what assessment is needed before it leaves Quebec. A lighting network holds little personal information on its own, but the platform sits inside the municipal IT estate and is assessed with it.

    Being able to state exactly where the data resides, and under whose control, is the simplest way to answer the residency question in that assessment.

  2. Two hosting models, one platform

    Both run the same platform and the same node firmware. The choice changes where the data lives, not what operators see.

    • Certified cloud hosting, with data residency in Canada.
    • On-premise deployment on the municipality’s own infrastructure, for full sovereignty over the data.
  3. Security in the network itself

    The figures below are the ones printed in the current node and gateway datasheets.

    • AES-128 encryption on the private radio network between nodes and gateways; AES-256 available with the Digi XBee PRO radio option.
    • Wi-SUN FAN 1.1: AES-128 (CCM) at the link layer, plus 802.1X/EAP-TLS certificate-based mutual authentication with keys rotated periodically by the border router.
    • Each gateway has its own passwords, certificates and keys, stored by Dimonoff with restricted access; server API access is protected by X.509 certificates with proof of possession.
    • Each node is individually serialized with its own address, and its firmware can be upgraded over the air.
    • Platform access: named user accounts, OAuth 2.0 authentication, role-based privileges per user.
  4. Updates under the customer’s control

    Firmware is updated over the air across the whole fleet, with a change notice and the customer’s approval before deployment. Nodes keep their schedule locally if the link drops, so a network or server outage does not turn the lights off.

  5. What is documented, and what is not claimed

    Documented: the SOC 2 Type II audit at the Groupe Vectanor level, and the UL, CSA, DLC and RoHS listings of the nodes, with their file numbers, in the datasheets. Not claimed on this site: certifications it does not display, such as ISO 27001, IEC 62443 or TALQ. If a tender requires one of those, ask, and the answer will be the current status rather than a badge.

This page describes the system as built. It is not legal advice on Law 25 or on any other privacy law; a municipality’s own privacy officer or counsel makes that assessment.

Questions about data and hosting

Can the platform run entirely inside the municipality’s own network?

Yes. Dimonoff | SCMS can be deployed on-premise, on the municipality’s own infrastructure, with the same features as the cloud version. Data then resides wherever the municipality runs its servers.

Is the data stored in Canada?

In the cloud model, hosting is certified and the data resides in Canada. In the on-premise model, it resides on the municipality’s own infrastructure.

Who can access the platform and the API?

Named user accounts with role-based access control and OAuth 2.0 authentication for the platform. Access to the server API is protected by X.509 certificates with proof of possession.

Bring your IT team to the demo.

We will walk through hosting, authentication and the API with the people who will assess them.