Personal Data and Privacy

The MetaDefender Industrial Firewall is a network security appliance. It is designed to protect operational technology (OT) networks and, by design, collects and stores only the minimal personal data required to operate and be administered securely. This page describes what data the appliance collects, uses, and stores, how that data is protected, and how it can be deleted.

Data collected and stored

The appliance stores the following personal data:

  • User account data: For administrator and operator accounts created by the customer: username, assigned role / privilege level, and the account password. Passwords are never stored in plaintext; they are stored only as a salted PBKDF2-SHA256 hash.

  • Log and audit data: Authentication events (logins, logouts, failed attempts, lockouts), configuration changes, and system and security events. These records include the username, source IP address, and a timestamp.

  • Central management (optional): If the operator enrolls the appliance in My OPSWAT Central Management, device identity and health information are shared with the management platform for administration and licensing purposes. This is optional and is only active when the operator enrolls the device.

Data the appliance does not collect

  • The appliance does not inspect, extract, or store the personal content of the network traffic it protects. Deep packet inspection classifies industrial protocol operations; it does not retain payload content.

  • Network event logs contain network metadata (addresses, protocols, event types) only — not the contents of user communications.

  • In its default configuration, the appliance transmits no personal or usage data to OPSWAT or any third party.

How personal data is protected

  • At rest: Passwords are protected with salted PBKDF2-SHA256 hashing. Stored authentication secrets (for example, RADIUS/TACACS+ shared secrets) are encrypted with AES-256-GCM. System backups that contain configuration and account data are password-protected.

  • In transit: All administrative access to this data occurs over encrypted channels: HTTPS/TLS for the web interface and API, and SSH for the command-line interface.

  • Access control: Access to account and log data requires authentication and is governed by role-based access control; account data is filtered by the caller's privilege level so that non-administrative users cannot read other users' data.

Deleting personal data and equipment disposal

  • Individual accounts: An administrator can delete individual user accounts at any time through the management interface.

  • Full removal / disposal: A factory reset permanently removes all stored personal data — user accounts and credentials, configuration, certificates, audit trails, event logs, and packet captures — returning the appliance to its factory state. A factory reset can be performed from the management interface or through the physical USB reset procedure, and requires no vendor involvement. This allows equipment to be safely decommissioned, transferred, or returned for service.

Reference

OPSWAT's handling of personal data is governed by the OPSWAT Privacy Policy.