Security and Data Protection
Secure access, uncompromising protection.
Global leaders in smart access solutions, committed to the highest standards of physical security and digital resilience. We don’t just open doors; we safeguard your sensitive data with industry-leading access control security.
As a trusted provider of advanced electronic locking solutions and cloud-based access platforms, Salto plays a key role in safeguarding physical and digital environments through robust access control cybersecurity. By securely managing sensitive data such as user credentials, access logs, and system configurations, Salto ensures seamless and reliable secure access control solutions for its clients.
Our Security Framework
Cybersecurity is the foundation of our innovation at Salto. It is a strategic pillar that ensures Salto delivers seamless, safe, and reliable access solutions—protecting the people and places that matter most, across any application, anywhere in the world.

GRC
We use first-class GRC (Governance, Risk, and Compliance) software to monitor and manage risks in real-time.

Cyber Resilience
Periodic penetration testing and continuous improvement cycles ensure our hardware and software resist evolving threats.

ISMS
Our Information Security Management System is mandatory across Salto, ensuring every employee upholds your privacy.
Security Certifications
Industry-Leading Compliance
Salto adopts the highest standards for its products, services, and processes in general, by developing security policies and standards aligned to international standards such as ISO 27001, NIST Cybersecurity Framework or ETSI 303 645 — reinforcing our commitment to access control security and data protection across every solution.
Our Information Security Management System (ISMS) is certified to ISO/IEC 27001. This confirms a risk-based approach to managing sensitive data across our cloud platforms, software applications, and physical infrastructure, making Salto a trusted ISO 27001 access control provider.
See certificationsSalto mobile apps (Homelok, Salto KS, and Justin) have achieved the Mobile Application Security Assessment (MASA) certification via Google-authorized labs, validating that our mobile access control security meets the highest industry benchmarks.
See certificationsWe hold two prestigious Kitemarks from the British Standards Institution for IoT access control security:
- Enhanced Level IoT Kitemark™: Verifies hardware meets ETSI EN 303 645 for advanced cybersecurity in smart lock and electronic access control devices.
- Secure Digital Applications Kitemark™: Certifies that ProAccess Space and our mobile apps meet OWASP ASVS standards for secure coding.
Data Privacy & Infrastructure
At Salto, privacy is more than a policy—it is a priority. We are committed to protecting personal data through secure‑by‑design engineering, strong encryption, and strict adherence to international privacy regulations. Our infrastructure is built to keep your information secure, confidential, and always under your control — delivering full data protection for access control systems.

Committed to Security & Compliance
Access our full library of security policies, security advisories, privacy statements, and organizational standards to see how we protect your enterprise with Salto’s access control security framework.
Explore Our Security PoliciesCommon security questions - FAQs
Yes. Salto is ISO/IEC 27001 certified for its Information Security Management System (ISMS). This certification covers our cloud services, software platforms, and supporting infrastructure, ensuring consistent access control security across the SALTO ecosystem.
Our ISO 27001 ISMS follows a risk based approach, including robust policies, technical and organizational controls, incident response, and continuous monitoring for the design, development, operation, and support of our electronic access control solutions.
You can find the publicly available certification details on the Salto Certifications page
Salto protects user data with strong encryption, secure authentication, and privacy focused controls. Data is encrypted at rest with AES256 and in transit with TLS 1.3. We apply robust IAM policies, including MFA, to prevent unauthorized access. All processing follows strict GDPR data privacy requirements.
Yes. Salto’s is GDPR compliant, ensuring strong data privacy across all global operations. We apply privacy-by-design principles and enforce strict controls to protect personal data throughout the entire access control process.
Salto holds several key security certifications across its access control ecosystem:
- ISO/IEC 27001 — Certification of our Information Security Management System, covering cloud services, software platforms, and supporting infrastructure
- BSI Enhanced Level IoT Kitemark™ — Independent validation that SALTO smart locks and IoT devices meet advanced cybersecurity and physical security requirements.
- Google MASA (Mobile App Security Assessment) — Certification confirming that several SALTO mobile apps meet strong mobile app security and privacy requirements.
These certifications demonstrate Salto’s commitment to robust security across hardware, software, cloud, and mobile experiences.
Salto mobile apps are highly secure and independently validated. Independent validation by Google Authorized Labs confirms that several of our apps are certified under Google’s MASA (Mobile App Security Assessment) program, demonstrating strong protection against mobile threats. They are also developed following OWASP mobile security and ASVS guidelines, ensuring secure communication, data protection, and resistance to tampering.
Yes. Salto has an ongoing cybersecurity awareness program that includes regular employee training, internal communications, and periodic awareness campaigns. These activities focus on security best practices, phishing awareness, and helping employees recognize and avoid common cyber threats. The program is delivered throughout the year to ensure continuous awareness and UpToDate security knowledge across the organization.
Salto follows a formal incident management procedure aligned with ISO 27001. When a security incident is detected, it is promptly assessed, escalated, and managed through a structured process that includes containment, mitigation, documentation, and communication. This ensures that any incident with potential impact on sensitive data is handled quickly, securely, and in accordance with industry best practices.







