Built-in redundancy and safety checks to ensure driver safety and vehicle functionality at all times.
Sophisticated, multi-layered security using the latest approaches to quickly identify, stop and mitigate the impact of cyber attacks.
Data privacy & security is designed into every solution, from in-vehicle software & firmware to encryption in the cloud.
Operational principles that follow rigorous internal procedures and industry best practices to keep every customer safe & secure.
The only ISO 26262 certified (by UL) over-the-air software update product with an ASIL-D rating for deploying software and firmware updates to any ECU with safety and confidence.
Customizable "safe state" checks to ensure road vehicles are in a safe state (not in motion) before and after performing any ECU software updates that could result in a human safety hazard.
Sibros' system ensures only valid versions of OEM signed software or firmware can be installed to mitigate risks of incorrect parameter settings or malware intrusion.
Continuous monitoring of ECUs to ensure they are fully and correctly programmed, operating as intended.
We ensure the functional safety of all new products and concepts with extensive concept testing and analysis prior to customer release.
As one of the first and only connected vehicle platform providers with ISO 21434 certification, Sibros leads the way in integrating robust cybersecurity practices to ensure the highest levels of safety, security, and customer trust.
Sibros has meticulously developed an application security framework that is secure by design and compliant with the stringent security protocols as outlined in ISO 27034.
Technology features and mechanisms for Cybersecurity Management Systems (CSMS) and Software Update Management Systems (SUMS) to help OEMs achieve R155 and R156 regulatory compliance.
Technology features and mechanisms for Cybersecurity Management Systems (CSMS) and Software Update Management Systems (SUMS) to help Indian OEMs achieve AIS-189 and AIS-190 regulatory compliance.
Our systems employ the compromise-resistant Uptane framework, designed to provide multi-layer cybersecurity and threat protection against bad actors for over-the-air software updates in ground vehicles.
Utilization of HTTPS/MQTTS to ensure secure and reliable data exchange between vehicles and the cloud.
Approval and authentication of commands and updates to require signature keys across multiple access points and users to prevent tampering and unauthorized usage.
All software versions, update packages, system changes, and associated vehicles utilize unique identifiers for consistency, transparency, verification, and traceability.
Sibros’ multi-layer authentication & security approach protects against a multitude of malicious activities such as eavesdropping, drop-request, slow-retrieval, freeze attacks, rollback attacks, and more.
Compliance with user privacy and data rights as outlined in the EU General Data Protection Regulation (GDPR) and other comparable international data protection standards.
Compliance with customer consent and right-to-use requirements for data collection and storage as outlined in the California Consumer Privacy Act.
Certified for Information Security Management Systems and best practices that safeguard all forms of information and protect the integrity, confidentiality and availability of data.
Compliance with the European automotive standard for a consistent approach to enterprise information security systems.
Certification by the American Institute of CPAs (AICPA) Systems and Organization Controls (SOC) for internal controls and efficacy of how we safeguard customer data.
Certified for Quality Management Systems (QMS) and frameworks to continually improve our products and services we deliver to you.
Our dedicated Risk Committee oversees the detection, assessment, and documentation of potential threats per the guidelines outlined in our Incident Response Policy.
Ongoing communication and training is required across the organization on all new operational procedures, obligatory compliance topics and related best practices.
All employees undergo a thorough vetting process, including multiple interviews, a criminal background check, and introductory training. Upon departure, employee access to company systems, services, and applications is immediately disabled.
All access needs authorization and is granted on a need-to-know basis. All employees are background checked as part of their onboarding process.
Sibros follows an approach of security designed from the ground up and built into the DNA of the product. This includes in-vehicle secure communications and secure storage / HSM integrations.
Our solution is assessed to TISAX, SSAE 16/18 SOC 2 Type 2, ISO 26262 (ASIL-D) in place with ISO 27001, ISO 21434, and ISO 24089 in progress. Sibros also addresses and supports security regulations such as UNECE WP.29 R155 and R156, with AIS 189, AIS 190 under review; as well as privacy regulations such as GDPR and CCPA, with Indian DPDP under review.
Sibros acts as a data processor. The OEM is the data controller.
All changes for cloud and firmware are reviewed.
Sibros has a very well defined incident management process, and security incident management and breach response processes.
With the following reviews and assessments:
Support for 0x27 and key exchange, secure storage and symmetric key handling to be determined by target ECU.
The following are used:
Sibros Armor includes the following checks and failsafes:
Sibros primarily uses a Globally Unique Identifier (GUID) to create a link between device identification information such as Vehicle Identification Number (VIN) / Electronic Serial Number (ESN) and the data collected by Deep Logger, Deep Updater, and Deep Commander.
Security is designed into the solution. Additionally, it is assessed to TISAX, SSAE 16/18 SOC 2 Type 2, ISO 26262 in place with ISO 27001, ISO 21434, and ISO 24089 in progress.
Log files are archived and optionally compressed. They are also handled securely and not directly uploaded into the system. The only reference information is in the system, and the S3 bucket is only used for storage of files that are uploaded as GUID’s (Globally Unique Identifiers).
Uptane is the first security framework for automotive OTA updates that provides serious compromise resilience, meaning that it can withstand attacks on servers, networks, keys, or devices. The differences are as follows:
The following measures are taken:
The following measures and practices are implemented:
The following are used: