Edge-first inference
Vision, time-series and process models run on factory-edge hardware. Cloud is for training and fleet management, and is optional.
A footwear plant carries brand quality agreements, product-liability exposure and the most protected IP in the business — patterns, lasts and construction specs. Footeon is designed around that reality.
Where we are today, stated plainly, including what is still in progress.
The default is that nothing leaves the plant that does not have to.
Vision, time-series and process models run on factory-edge hardware. Cloud is for training and fleet management, and is optional.
Patterns, lasts, BOMs and telemetry are scoped per tenant and per entity. Nothing is used to train another customer’s models.
TLS 1.3 in transit, AES-256 at rest, customer-managed keys available on enterprise agreements.
Audit and quality records retained for the product-liability window you specify; telemetry retention configurable per plant.
On-premises deployment with zero telemetry egress for brands whose IP cannot leave controlled infrastructure.
Documented deletion path for tenant data and derived model artefacts on contract termination.
A security review usually reduces to one question: can you show me why the machine did that? Here is the answer for the one autonomous decision that paused in RUN-4417.
Requested at 10:31:10, approved at 10:34:14 by the shift quality engineer, executed at 10:34:20.
line-b/rh-04 humidity series, adhesive datasheet AD-22 §4.2, twin-predicted bond margin at 64 °C versus 66 °C.
Written to the append-only audit store, signed, and exported nightly to the customer GRC system.
If the approval SLA had expired, the agent would have held the previous validated recipe and stopped the affected pairs rather than proceeding.
Every Footeon decision that touches a cut, a mould, a last or a bond line is recorded as plan, thought, action and observation — with the material lot, sensor reading and spec clause that justified it. Quality engineers can replay any pair.
Traces are retained for the full product-liability window and exported to your MES and quality system.
Four independent mechanisms, so no single failure produces an uncontrolled write.
Roles map to how a plant actually works, not to a generic SaaS permission model.
| Role | View runs | Change autonomy | Approve validated params | Export audit |
|---|---|---|---|---|
| Operator | Own station | No | No | No |
| Line supervisor | Own line | Up to recommend | No | No |
| Process engineer | Plant | Up to act-with-approval | Moulding | Own plant |
| Quality engineer | Plant | No | Bonding, lasting, moulding | Own plant |
| Plant manager | Plant | All levels | No | Own plant |
| Security admin | Metadata only | No | No | All plants |
An autonomy layer is only as safe as the artefacts it runs.
Models are signed at build time and signature-verified before the edge runtime loads them.
Golden datasets and LLM-as-judge evaluation gate every model and prompt change in CI.
Any line can be reverted to a previous model version without touching the machine controls.
The runtime holds only the machine scopes its agents need, enforced outside the model.
Retrieved documents are treated as data, never as instructions; tool calls are allow-listed.
Input and output distributions monitored per line; drift raises an alert before it raises a defect.
Targets published so you can hold us to them.
Everything above, plus the identity, residency and reporting an enterprise risk committee expects.
Only if you choose. Inference runs on factory-edge servers, and Enterprise deployments can run fully on-premises or in your VPC with no telemetry egress. Brand IP — patterns, lasts, construction specs — is tenant-isolated and never used to train models for another customer.
It stops and asks. Every agent runs at a configured autonomy level: observe, recommend, act-with-approval, or act. Bonding, lasting and any parameter under a brand or safety validation defaults to act-with-approval, and every approval is written to an immutable audit log with the sensor evidence that triggered it.
Agents are bounded by guardrails and schema validation, they cite the datasheet or spec clause behind a decision, and they fail closed to the last known-good recipe. Continuous evaluation against golden datasets gates every model and prompt change in CI before it reaches a plant.
No. Footeon is a software and factory-edge autonomy layer that sits on top of the machines you already run. We connect over OPC UA, MQTT, Modbus TCP and vendor SDKs, read sensors and vision, and write setpoints back through the controls you already trust — with approval gates on any validated parameter.
We answer questionnaires, run architecture reviews with your OT team, and support on-prem proofs of concept.