All topics
On this page

Your team members can access your organisation's data, each with the permissions of their role, and so can ModbusCloud for support. You decide who else sees anything, through a public link, alert emails, an API key or a webhook.

Where the data is stored

The gateway sends its readings to a broker, and from there they go into the database. The table shows where the broker, the database and the portal run.

ComponentWhat it doesLocation
BrokerReceives the readings from the gateway over MQTT over TLSFrankfurt, Germany
DatabaseStores readings, alerts, settings and accountsIreland
Portal and REST APIShow the readings in the browser and pass them on to integrationsIreland

The gateway opens the connection to the broker itself, outbound only. Which port has to be open for this is described in Network requirements for the gateway. Which parties process data for ModbusCloud is described in the data processing agreement.

Separated per organisation

Each organisation sees only its own gateways, readings, alerts and settings. The separation is in the database itself (row-level security). When the portal requests data with your account, it receives only rows from the organisation you are a member of.

An API key belongs to one organisation and gives access only to the data of that organisation. Each team member signs in with their own account. How to protect that account is described in Secure your sign-in and account.

Roles in your organisation

Each team member has one role. All team members see the gateways, readings and alerts of all your customers, whatever their role.

An owner or admin manages team members, API keys and webhooks. A technician sets up gateways, Modbus devices, alert rules and automations. A team member with the read only role views and downloads readings but changes nothing. The full table is in Team members and roles.

Control and API keys

Writing to registers is off by default on every gateway. An owner, admin or technician requests it per gateway on the Control tab. Only ModbusCloud turns it on.

As long as control is off, nothing sends a value to the Modbus devices behind that gateway, not even an automation, a dashboard button or an API integration. If a gateway moves to another organisation, control is off again there. The request is described in Control registers from the portal.

API keys are under Settings > API keys. The portal shows a new key once and stores only a SHA-256 hash and the first 12 characters. A key may do only what its Permissions allow. A revoked key stops working immediately.

What your organisation shares itself

Through these routes, data ends up outside the portal. The table shows who then sees the data and how you stop it.

RouteWho sees the dataStop access
Public link of a dashboardAnyone with the link, plus the password if you set oneTurn off Public link
Alert emailEvery address that receives the alert email, including a separate address without an accountRemove the address from the alert email recipients
API keyThe system that uses the key, within its PermissionsRevoke the key
WebhookThe address you enter for the webhookTurn off or delete the webhook

A report email contains no readings. The button in the email opens the report only after sign-in.

ModbusCloud and your data

Your organisation remains the owner of the readings and of your customers' data. This is stated in article 8 of the terms and conditions. ModbusCloud processes the data as a processor, under the data processing agreement.

For support, ModbusCloud has an account with the admin role in every organisation. That account does not appear in the Members list under Settings > Team members, and nobody in your organisation can change or delete it. How long readings are kept and how to take them with you is described in Retention periods and exporting your data.

Updated on 7 October 2026

Still stuck?

Email or call us. Include the serial number of the gateway, so we can take a look straight away.

Go to support