Security of a devices open port

I wondering about the security of open ports on devices using Hologram sims.
For a device to receive messages from the Hologram cloud a TCP/IP port must remain open. I understand that the device’s IP address is not publically accessible but what is the scope of that access? Obviously, the hologram servers have access to be able to forward the message to the device. Is there device-to-device access between Hologram devices using the hologram APN?

No, we do not route traffic between devices on our APN specifically because of the security mess that would cause. It can only be reached by our servers. External internet cannot reach the device except via Spacebridge access and only users on your organization can open a tunnel to the device in this manner.

Sounds good, that is the info I was looking for.

