Governance

Ethical Guidelines

Last updated: June 2026

Iodibase is built on the belief that IoT infrastructure should be transparent, secure, and respectful of user autonomy. These guidelines govern how we design, operate, and evolve our platform.

We are committed to responsible engineering practices that prioritize data sovereignty, environmental sustainability, and the long-term reliability of the IoT ecosystem.

1. Data Sovereignty

Your data belongs to you — not us, not any third party, not any government without due process.

  • All customer data is stored exclusively within the European Union
  • We never sell, license, or share customer telemetry data
  • Data exports are available in open formats at any time
  • We maintain the ability to operate without US-based cloud providers
  • Customer data is cryptographically isolated per workspace

2. Transparency

We believe in radical transparency about how our platform works and how we operate.

  • Pricing is published and predictable — no hidden fees or surprise charges
  • System status and incidents are publicly documented
  • Our security practices and audit results are published annually
  • We disclose government data requests in our transparency report
  • API contracts are versioned and backward-compatible within major versions

3. Security by Default

Security is not a feature — it is the foundation. Every design decision starts with security.

  • End-to-end encryption is enabled by default, not optional
  • Principle of least privilege applies to our own internal access
  • Vulnerability disclosure program with responsible disclosure rewards
  • Regular third-party security audits, results published
  • Incident response procedures tested quarterly

4. Environmental Responsibility

IoT infrastructure generates significant energy consumption. We are committed to minimizing our environmental footprint.

  • Our infrastructure runs on renewable energy
  • We publish annual energy consumption and carbon offset reports
  • Efficient system design reduces compute waste — Rust-first architecture
  • Data retention policies encourage minimal storage
  • Hardware lifecycle management with responsible e-waste disposal

5. Open Standards and Interoperability

We build on open protocols and standards to prevent vendor lock-in and ensure long-term compatibility.

  • MQTT, HTTP/REST, and other open protocols for device connectivity
  • Apache Iceberg and other open table formats for data storage
  • OpenAPI specifications for all REST endpoints
  • No proprietary binary formats for data exchange
  • Migration tools for moving data to other platforms

6. Responsible AI

When AI features are introduced, they will follow these principles:

  • AI-assisted features are opt-in, never default
  • Customer data used for AI processing is anonymized and never stored
  • AI model decisions are explainable and auditable
  • Human review remains available for all AI-generated recommendations
  • We comply with the EU AI Act and emerging AI regulations

7. Supply Chain Integrity

We take responsibility for our software supply chain.

  • All dependencies are audited and pinned to verified versions
  • SBOM (Software Bill of Materials) published for each release
  • Reproducible builds for our core Rust components
  • Third-party integrations are reviewed for privacy and security compliance
  • We prefer open-source and EU-based suppliers where possible

8. Accessibility and Inclusion

IoT infrastructure should be accessible to engineers of all backgrounds and abilities.

  • Console UI targets WCAG 2.1 AA compliance
  • API documentation is available in multiple languages
  • Pricing tiers designed to support individual developers and small teams
  • Community support channels alongside paid support options

9. Enforcement and Accountability

These guidelines are not aspirational — they are operational requirements.

  • Every product decision is evaluated against these guidelines
  • Annual review and update of these guidelines
  • Third-party audits of our compliance with these principles
  • Public reporting on guideline adherence

10. Contact

If you have questions about our ethical guidelines or concerns about our practices, contact us at: