SALTO WECOSYSTEM
Aide et Assistance

Sélectionnez vos paramètres de localisation et de langue

Switzerland

|

Français

Global

Germany

Switzerland

United Kingdom

Ireland

France

Netherlands

Belgium

Spain

Portugal

Italy

Russia

Poland

Czech Republic

Denmark

Sweden

Norway

Finland

USA

Canada

Mexico

Colombia

Chile

China

Korean

Singapore

Hong Kong

Vietnam

Japan

Australia / New Zealand

UAE

Saudi Arabia

South Africa

India

Security and Data Protection

Secure access, uncompromising protection.

Global leaders in smart access solutions, committed to the highest standards of physical security and digital resilience. We don’t just open doors; we safeguard your sensitive data with industry-leading access control security.

As a trusted provider of advanced electronic locking solutions and cloud-based access platforms, Salto plays a key role in safeguarding physical and digital environments through robust access control cybersecurity. By securely managing sensitive data such as user credentials, access logs, and system configurations, Salto ensures seamless and reliable secure access control solutions for its clients.

Our Security Framework

Cybersecurity is the foundation of our innovation at Salto. It is a strategic pillar that ensures Salto delivers seamless, safe, and reliable access solutions—protecting the people and places that matter most, across any application, anywhere in the world.

GRC

We use first-class GRC (Governance, Risk, and Compliance) software to monitor and manage risks in real-time.

Cyber Resilience

Periodic penetration testing and continuous improvement cycles ensure our hardware and software resist evolving threats.

ISMS

Our Information Security Management System is mandatory across Salto, ensuring every employee upholds your privacy.

Security Certifications

Industry-Leading Compliance

Salto adopts the highest standards for its products, services, and processes in general, by developing security policies and standards aligned to international standards such as ISO 27001, NIST Cybersecurity Framework or ETSI 303 645 — reinforcing our commitment to access control security and data protection across every solution.

Our Information Security Management System (ISMS) is certified to ISO/IEC 27001. This confirms a risk-based approach to managing sensitive data across our cloud platforms, software applications, and physical infrastructure, making Salto a trusted ISO 27001 access control provider.

See certifications

Salto mobile apps (Homelok, Salto KS, and Justin) have achieved the Mobile Application Security Assessment (MASA) certification via Google-authorized labs, validating that our mobile access control security meets the highest industry benchmarks.

See certifications

We hold two prestigious Kitemarks from the British Standards Institution for IoT access control security:

  • Enhanced Level IoT Kitemark™: Verifies hardware meets ETSI EN 303 645 for advanced cybersecurity in smart lock and electronic access control devices.
  • Secure Digital Applications Kitemark™: Certifies that ProAccess Space and our mobile apps meet OWASP ASVS standards for secure coding.
See certifications

Data Privacy & Infrastructure

At Salto, privacy is more than a policy—it is a priority. We are committed to protecting personal data through secure‑by‑design engineering, strong encryption, and strict adherence to international privacy regulations. Our infrastructure is built to keep your information secure, confidential, and always under your control — delivering full data protection for access control systems.

GDPR Compliance

Our operations, cloud platforms and applications are fully aligned with the European Union’s General Data Protection Regulation (GDPR), providing the world’s most stringent data privacy protections to all our users globally. Salto offers GDPR compliant access control as standard across all its platforms.

Encryption Standards

By utilizing end-to-end encryption, we ensure that personal data is protected from unauthorized access at every touchpoint. All sensitive data is protected using industry-standard AES-256 (at rest) and TLS 1.3 (in transit).

Cloud Security

Our cloud-based platforms are hosted in secure, hardened environments, using strong end-to-end encryption, IAM (Identity and Access Management), MFA (Multi-Factor Authentication), and regular security audits, meeting high standards for data privacy and system integrity for customers. Our cloud access control security architecture ensures your data remains protected at every layer.

Trusted SOC providers

We partner with SOC‑certified cloud providers to ensure robust operational security, continuous monitoring, and independently validated controls for our hosted services and data.

Security Standards & Compliance

Strong security framework aligned with international security standards and regulations. ISO 27001, NIS2; OWASP best practices.

Hardware Security

Our hardware includes built-in protections that keep each device secure, authentic, and resistant to tampering — combining physical security and cybersecurity in every electronic access control device.

Secure Development (SDLC)

We integrate security at every stage of our development lifecycle, ensuring that each product update is thoroughly reviewed, tested, and validated against modern security and privacy requirements.

Access Control & Identity Protection

We enforce strong authentication and role‑based access controls to ensure that personal data is only accessible to authorized individuals and systems.

Common security questions - FAQs

  • Yes. Salto is ISO/IEC 27001 certified for its Information Security Management System (ISMS). This certification covers our cloud services, software platforms, and supporting infrastructure, ensuring consistent access control security across the SALTO ecosystem.

    Our ISO 27001 ISMS follows a risk based approach, including robust policies, technical and organizational controls, incident response, and continuous monitoring for the design, development, operation, and support of our electronic access control solutions.

    You can find the publicly available certification details on the Salto Certifications page

  • Salto protects user data with strong encryption, secure authentication, and privacy focused controls. Data is encrypted at rest with AES256 and in transit with TLS 1.3. We apply robust IAM policies, including MFA, to prevent unauthorized access. All processing follows strict GDPR data privacy requirements.

  • Yes. Salto’s is GDPR compliant, ensuring strong data privacy across all global operations. We apply privacy-by-design principles and enforce strict controls to protect personal data throughout the entire access control process.

  • Salto holds several key security certifications across its access control ecosystem:

    • ISO/IEC 27001 — Certification of our Information Security Management System, covering cloud services, software platforms, and supporting infrastructure
    • BSI Enhanced Level IoT Kitemark™ — Independent validation that SALTO smart locks and IoT devices meet advanced cybersecurity and physical security requirements.
    • Google MASA (Mobile App Security Assessment) — Certification confirming that several SALTO mobile apps meet strong mobile app security and privacy requirements.

    These certifications demonstrate Salto’s commitment to robust security across hardware, software, cloud, and mobile experiences.

  • Salto mobile apps are highly secure and independently validated. Independent validation by Google Authorized Labs confirms that several of our apps are certified under Google’s MASA (Mobile App Security Assessment) program, demonstrating strong protection against mobile threats. They are also developed following OWASP mobile security and ASVS guidelines, ensuring secure communication, data protection, and resistance to tampering.

  • Yes. Salto has an ongoing cybersecurity awareness program that includes regular employee training, internal communications, and periodic awareness campaigns. These activities focus on security best practices, phishing awareness, and helping employees recognize and avoid common cyber threats. The program is delivered throughout the year to ensure continuous awareness and UpToDate security knowledge across the organization.

  • Salto follows a formal incident management procedure aligned with ISO 27001. When a security incident is detected, it is promptly assessed, escalated, and managed through a structured process that includes containment, mitigation, documentation, and communication. This ensures that any incident with potential impact on sensitive data is handled quickly, securely, and in accordance with industry best practices.