Security · Tenancy, residency and the AI boundary | ENGINPILOT
PLATFORM / 08 — SECURITY

Engineering data stays inside the boundary it entered.

Asset records, design basis documents and operating history are among the most sensitive material a plant holds. ENGINPILOT isolates them per tenant, keeps them in a named jurisdiction, and never uses them to train a model any other customer can reach.

TENANCY
Isolated graph, twin and keys per customer
RESIDENCY
Region chosen at contract, not at runtime
ENCRYPTION
AES-256 at rest, TLS 1.3 in transit
AI BOUNDARY
No customer data trains a shared model
01 — TENANCY

One tenant, one boundary, one key

Each customer receives a dedicated knowledge graph, a dedicated twin state store and a dedicated encryption key. Platform code is shared; customer data is not. There is no cross-tenant query path — not for support, not for analytics, not for model improvement.

GRAPHSeparate EIG instance per tenant
KEYSCustomer-managed keys supported (BYOK)
SUPPORTBreak-glass access is time-boxed and logged
ISOLATION MODEL · PER TENANT TENANT A TENANT B TENANT C EIG GRAPH TWIN STATE KEY · CMK-A EIG GRAPH TWIN STATE KEY · CMK-B EIG GRAPH TWIN STATE KEY · CMK-C NO CROSS-TENANT QUERY PATH SHARED PLATFORM CODE — NO CUSTOMER DATA FIG 1 / TENANT ISOLATION · NTS CMK = CUSTOMER-MANAGED KEY EP-SEC-001
AI DATA BOUNDARY SHARED FOUNDATION MODEL TENANT BOUNDARY ASSET RECORD DESIGN BASIS OPERATING LOG INFERENCE IN-BOUNDARY AUDIT LOG RETAINED BLOCKED — NO TRAINING EGRESS FIG 2 / AI DATA BOUNDARY · NTS INFERENCE RUNS IN-BOUNDARY; WEIGHTS ARE READ-ONLY EP-SEC-002
02 — THE AI BOUNDARY

Models read customer data. They never carry it out.

Inference runs inside the tenant boundary against read-only model weights. Prompts, retrieved documents, asset records and generated recommendations stay in the tenant. Nothing is written back into a shared model, and no customer's operating history improves another customer's answers.

TRAININGCustomer data is excluded by architecture, not by policy setting
RETENTIONPrompt and response history retained in-tenant, deletable on request
PROVENANCEEvery model output carries its sources, its confidence and its physics verdict
03 — DEPLOYMENT

Three topologies, one security model

Where the platform runs is a procurement decision. The security model is designed so that it does not change between topologies — isolation, attribution and physics validation are architected to behave identically in all three, and each is verified in the topologies currently deployed with design partners.

STATUS DESIGN PARTNER · REGIONAL SAAS AND PRIVATE CLOUD · AIR-GAPPED IN DEVELOPMENT
REGIONAL SAAS
Managed, single region

Data resides in one named region for the life of the contract. Fastest to deploy; standard for pilots and multi-site rollouts.

PRIVATE CLOUD
Your subscription, your account

Deployed into the customer's own cloud account under the customer's own controls, keys and network policy.

AIR-GAPPED
No outbound connectivity

On-premises install for OT-segmented and defence-adjacent sites. Model weights and reference libraries arrive by signed offline bundle.

04 — ACCESS AND ATTRIBUTION

Every action is attributable to a named person

Engineering accountability requires knowing who approved what, on what evidence, at what time. Access is role-scoped and the audit record is append-only.

ROLE
SCOPE
CAN APPROVE ACTION
Viewer
Read asset records, twins and calculation history
NO
Engineer
Run solver calls, request validations, annotate findings
WITHIN LIMITS
Responsible engineer
Accept or reject validated recommendations for owned assets
YES · SIGNED
Administrator
Manage identity, roles, keys and retention policy
NO
ENGINPILOT support
Break-glass only — customer-approved, time-boxed, fully logged
NO

Identity federates through SAML 2.0 or OIDC. SCIM provisioning keeps role membership synchronised with the customer's directory.

05 — COMPLIANCE POSTURE

Stated as of the date below, not aspirationally

Certification status is published as it currently stands, not as it is expected to stand. An audit that is still in progress is labelled as in progress, so a security reviewer can tell the difference between a completed certification and an intended one.

SOC 2 Type II
Security, availability, confidentiality
AUDIT IN PROGRESS
ISO/IEC 27001
Information security management
AUDIT IN PROGRESS
GDPR / DPDP Act 2023
Data protection, EU and India
COMPLIANT
IEC 62443
Industrial automation security, OT integration
ALIGNED

STATUS AS OF Q3 2026 · REVIEWED QUARTERLY

06 — WHERE IT SITS

Not a layer — a property of every layer

Security is not the seventh floor of the architecture. Isolation and attribution are enforced at the graph, at the solver, at PhysicsNET and at the agent layer independently, so a failure in one does not open the others.

ENFORCED AT
Knowledge graph — row-level tenant scope Solver — inputs bound to calling tenant Agent layer — retrieval scoped before inference
RECORDED
Who requested, and under which role What evidence the answer rested on Which physics verdict permitted the action
EXPORTABLE
Audit log to customer SIEM Full tenant export on termination Certified deletion with written confirmation

Send this to your security team before the technical evaluation.

The security pack contains the architecture description, data flow diagrams, subprocessor list, penetration test summary and a completed CAIQ, so review can run in parallel with the engineering assessment rather than after it.