Trust & Security

Your plant data does not have to leave your plant.

Most industrial AI security reviews stall on the same question: where does the data go? For PredCo the answer is usually nowhere — the platform installs inside your perimeter, and an air-gapped deployment needs no outbound connection at all. This page is written for the person doing your vendor review.

DeploymentOn-premise · Air-gapped
EgressOptional
Standing vendor accessNone

Security starts with where the software runs

Controls layered on top of a cloud-only product are a weaker guarantee than a product that never needed to move your data in the first place.

Your data does not have to leave your network
PredCo installs inside your perimeter. On-premise, air-gapped, private cloud, or hybrid are all first-class deployment models rather than paid upgrades, and an air-gapped install requires no outbound connection of any kind.
Inference runs where the data is
Vision and predictive models execute at the edge on NVIDIA Jetson / IGX or GPU hardware you supply. Camera feeds and process signals are processed locally; frames do not need to traverse a public network to be scored.
We read your systems, we do not replace them
Connectors read from SCADA, historians, ERP, CMMS, PLM, and existing RTSP/ONVIF cameras. Records of authority stay in the systems that own them, which keeps your existing controls and retention rules intact.
Data residency is a deployment choice
Where the platform runs — and therefore where every byte is stored and processed — is decided at install time and stated in the contract, including in-country deployment for sovereignty requirements.

Your identity provider stays the source of truth

PredCo does not maintain a parallel user directory. Accounts, groups, and session policy come from the identity provider you already run.

Authentication
SAML 2.0 and OIDC. Integrates with Azure AD, Okta, and equivalent enterprise identity providers.
Authorization
Role-based access control with granular permissions per role: engineer, reviewer, approver, auditor.
Tenancy separation
Strict separation between sites, business units, and external suppliers within the same deployment.
Session policy
Session lifetime, MFA enforcement, and password policy inherit from your identity provider.
Administrative access
PredCo staff hold no standing access to a customer deployment. Support access is granted by you, scoped, and time-bound.
Access review
Permission state is exportable for periodic access reviews and audit evidence.

What is stored, for how long, and how it is removed

Data in transit
TLS 1.2+ for all network communication, including between edge nodes and the core within your network.
Data at rest
Encryption at rest using the storage-layer encryption of the environment the platform is deployed into.
Retention
Retention windows are configured per data class at install and enforced by the platform, not by manual cleanup.
Deletion
Records can be deleted per asset, per site, or per supplier, with deletion recorded on the audit trail.
Personal data
Vision models measure events, not identities. No facial recognition and no biometric identification of workers.
Sub-processors
An air-gapped or on-premise deployment involves no sub-processor. Cloud deployments use the infrastructure provider you nominate.

An answer you cannot trace is not evidence

Industrial AI gets used in filings, audits, and safety decisions. That only works if every output can be explained, attributed, and reproduced months later.

Every figure traces back to its source
Lineage is captured through every aggregation and transformation, so any number on any filed report resolves back to the original sensor reading or document page it came from.
Nothing consequential is fully automatic
Confidence thresholds route uncertain cases to a named reviewer. Every accept, reject, and override is recorded against the person who made it.
Models are versioned, not swapped
The model registry tracks every version from training run to what is live in production, so you can state which model produced a given result on a given date.
Agents work inside the same controls
Autonomous agents act only through tools scoped by the same role permissions that apply to people, and every plan, call, and result is written to the audit trail.

Compliance frameworks we work to

We do not hold these certifications today, and we would rather say so than imply otherwise. They are customer-driven: where an engagement requires one, we complete it as part of onboarding, on a timeline agreed with you.

ISO 27001
Information security management
SOC 2 Type II
Security, availability, and confidentiality controls
GDPR
EU data protection, with a data processing agreement
India DPDP Act
Digital Personal Data Protection Act, 2023
Third-party penetration testing
Application and infrastructure testing
Coordinated vulnerability disclosure
Reporting and remediation process

The architecture is already built around the controls these frameworks test for — access control, lineage, retention, and audit trail are described in the sections above. If a certification is a gate for your procurement, raise it early and we will scope it into the engagement.

What we hand your security and procurement teams

Evaluations move faster when the documentation arrives before it is chased. Ask once and we send the whole set.

  • Security architecture documentation for your review pack
  • Completed vendor security questionnaires (CAIQ, SIG, or your own template)
  • Data processing agreement and sub-processor list
  • Deployment topology diagram for your network team
  • Technical specification suitable for a tender file
  • Named security contact for the duration of the evaluation
Role-based access and an audit trail across compliance workflows in PredCo
Now onboarding new deployments

Bring one problem. We'll show you the deployment.

A 30-minute working session with our engineering team. No slideware. Bring a real operational problem and leave with a concrete view of what a PredCo deployment looks like for your plant.

4 hrs
Average response time
4–6 wks
Kickoff to live pilot
On-prem
Sovereign deployment supported