Security Framework
Our security program is built on internationally recognized standards including ISO 27001, NIST cybersecurity framework, and industry best practices.
Encryption & Data Protection
In Transit: All data transmitted between components and users is encrypted using TLS 1.3.
At Rest: Sensitive data is encrypted using AES-256, with key rotation without downtime.
Mutual TLS: Equipment communications use mutual TLS authentication.
Access Control & Authentication
Single Sign-On: Enterprise SSO with MFA for all user accounts.
Least Privilege: Short-lived credentials per component; drivers only access bound targets.
Audit Trail: Every user action and confirmation is logged and traced to a person.
Infrastructure & Operations
Infrastructure as Code: Deployment scripts; secrets live in the orchestrator, never in repositories.
Observability: Structured logs and Prometheus metrics for security monitoring and incident response.
Regular Audits: Security assessments and penetration testing conducted regularly.
Incident Response
We maintain a documented incident response plan with defined procedures, communication protocols, and escalation paths. Critical security incidents are reported without undue delay.
Vulnerability Management
Disclosure Policy: We welcome responsible security disclosures. Please contact security@stellar-systems.eu.
Patch Management: Security updates are deployed to production within 48 hours of release.
Compliance
We maintain compliance with NIS2 Directive, EASA requirements for critical infrastructure, GDPR for data protection, and ISO 27001 for information security management.
Contact
- Security Issues
- security@stellar-systems.eu
- General Inquiries
- info@stellar-systems.eu
Stellar SAS – Building secure mission control infrastructure for critical space systems.