One tenant, one boundary, one key
Each customer receives a dedicated knowledge graph, a dedicated twin state store and a dedicated encryption key. Platform code is shared; customer data is not. There is no cross-tenant query path — not for support, not for analytics, not for model improvement.
Models read customer data. They never carry it out.
Inference runs inside the tenant boundary against read-only model weights. Prompts, retrieved documents, asset records and generated recommendations stay in the tenant. Nothing is written back into a shared model, and no customer's operating history improves another customer's answers.
Three topologies, one security model
Where the platform runs is a procurement decision. The security model is designed so that it does not change between topologies — isolation, attribution and physics validation are architected to behave identically in all three, and each is verified in the topologies currently deployed with design partners.
Data resides in one named region for the life of the contract. Fastest to deploy; standard for pilots and multi-site rollouts.
Deployed into the customer's own cloud account under the customer's own controls, keys and network policy.
On-premises install for OT-segmented and defence-adjacent sites. Model weights and reference libraries arrive by signed offline bundle.
Every action is attributable to a named person
Engineering accountability requires knowing who approved what, on what evidence, at what time. Access is role-scoped and the audit record is append-only.
Identity federates through SAML 2.0 or OIDC. SCIM provisioning keeps role membership synchronised with the customer's directory.
Stated as of the date below, not aspirationally
Certification status is published as it currently stands, not as it is expected to stand. An audit that is still in progress is labelled as in progress, so a security reviewer can tell the difference between a completed certification and an intended one.
STATUS AS OF Q3 2026 · REVIEWED QUARTERLY
Not a layer — a property of every layer
Security is not the seventh floor of the architecture. Isolation and attribution are enforced at the graph, at the solver, at PhysicsNET and at the agent layer independently, so a failure in one does not open the others.
Send this to your security team before the technical evaluation.
The security pack contains the architecture description, data flow diagrams, subprocessor list, penetration test summary and a completed CAIQ, so review can run in parallel with the engineering assessment rather than after it.