The obvious worry about an internet-connected sensor is that it becomes a way into a network, or that someone replaces what it runs.
- Units make outbound connections only. Nothing needs to reach them, so no inbound rule or port forward is required on a store's network.
- Each unit has its own credential, so one compromised device cannot speak for another. A credential can be rotated or revoked at any time.
- Firmware images are cryptographically signed and a unit refuses one whose signature does not verify — a compromised network cannot install its own software on your hardware.
- Units verify the server's TLS certificate rather than accepting any responder.
- Devices send measurements. They hold no personal data and store no customer records.
Cellular units don't touch the store network at all unless Store Wi-Fi is configured for the store — in which case they join it as an ordinary client only, still outbound-only, still falling back to cellular. Nothing inbound is ever required, which for many IT departments is the simplest possible answer to the question.
