Illustration of the KFAI security operations room - analysts at monitors around a shield emblem.

Trust / Security

Security, by default.

We connect to the systems running your plant, so earning your security team's trust is the product. Here is how your data is isolated, encrypted, governed, and retained - in plain terms.

Security controls

SOC 2 ALIGNED
ISO 27001 ALIGNED
GDPR
TLS 1.3
AES-256
MULTI-TENANT ISOLATED

We operate to SOC 2 Type II and ISO 27001 control frameworks and are GDPR-aligned. We are not yet certified and claim no certification; our control documentation and certification roadmap are shared during security review - request a brief below.

01

Tenant isolation

KaizenFlow is multi-tenant with strict logical isolation. Every database query is scoped by tenant ID, so one organization’s manufacturing data is never reachable by another. Isolation boundaries are verified through regular security review.

Multi-tenantLogical isolation
02

Encryption

Data is encrypted in transit with TLS 1.3 and at rest with AES-256. Connector credentials (MES, SCADA, ERP, historian) are encrypted with Fernet symmetric encryption and never logged in plaintext.

TLS 1.3AES-256Fernet
03

Authentication & access control

JWT-based authentication with configurable token lifetimes, role-based access control across four roles (Admin, Manager, Engineer, Viewer), and rate limiting on sensitive endpoints. Every recommendation and action is attributable and audit-logged.

JWTRBACAdminManagerEngineerViewer
04

Data ownership & retention

Your data is yours. Manufacturing metrics are retained per your organization settings (default 12 months) and audit logs for 24 months. On termination, all data is permanently deleted within 30 days following a data-export window.

05

AI subprocessors

AI analysis uses vetted model providers (OpenAI, Anthropic) under contractual data-protection obligations. We do not sell your data or use it to train third-party models. AI output is advisory - final decisions remain with your team. The full subprocessor list is in our Privacy Policy.

OpenAIAnthropic
06

Reliability & availability

We target 99.9% uptime and connect on top of your existing stack - no rip-and-replace, no single point of failure introduced into your line. Enterprise deployments support data-residency requirements and private VPC isolation.

99.9% uptimePrivate VPCData residency
07

Responsible disclosure

If you believe you have found a security vulnerability, email [email protected]. We acknowledge reports promptly, investigate every submission, and will not pursue good-faith researchers who follow coordinated disclosure.

Illustration of a KFAI-protected production line - engineers at a threat wall beside machines marked security active.

The questions your IT team will ask

What data actually leaves the plant? Only what each connector is scoped to read: process tags, event and state data, counts, timestamps, and the cost rates you provide for dollar math. KaizenFlow does not read control logic or recipe IP, and collects no employee personal data by default. Every connector's scope is visible to your admins, and data moves over TLS 1.3 with AES-256 encryption at rest.

Can KaizenFlow write to our PLCs or control systems? No. Connections are read-only by default and KaizenFlow does not send commands to the floor. Recommendations are routed to people, who act through your existing systems and procedures.

What happens if the internet connection drops? Nothing, on your floor. KaizenFlow observes - it does not control - so a connectivity outage never stops a line. Analytics resume when the connection does; where an edge adapter is deployed, reads continue locally and sync when the link returns. The exact behavior for your topology is covered in the security brief.

Is KaizenFlow SOC 2 certified? Not yet, and we will not imply otherwise. We operate to SOC 2 Type II and ISO 27001 control frameworks; alignment does not constitute certification, and certification work is on our roadmap. What we can share today: control documentation, architecture diagrams, the subprocessor list, and data-flow documentation - request the security brief.

Can our data stay in our own environment? Enterprise deployments support private VPC isolation and data-residency requirements. The standard platform is multi-tenant with strict logical, per-tenant isolation, where every query is scoped by tenant ID.

Is our data used to train AI models? We do not sell your data or use it to train third-party models. AI analysis runs through vetted providers (OpenAI, Anthropic) under contractual data-protection obligations. Aggregated, anonymized benchmarks may be used to improve the platform, as set out in our terms.

For your security review

Request a security brief.

Architecture diagrams, the subprocessor list, data-flow documentation, and current audit status - sent to your security and procurement teams.