Autonomy you can put in front of an auditor

A footwear plant carries brand quality agreements, product-liability exposure and the most protected IP in the business — patterns, lasts and construction specs. Footeon is designed around that reality.

  • Edge-first inference
  • Per-tenant isolation
  • Immutable audit log

Certifications and controls

Where we are today, stated plainly, including what is still in progress.

Certifications and posture

  • In progress SOC 2 Type II — audit window open [ASPIRATIONAL]
  • In progress ISO 27001 — controls implemented, certification pending [ASPIRATIONAL]
  • Supported GDPR — EU data residency and DPA available
  • Supported Per-tenant isolation for patterns, lasts and construction IP
  • Supported On-premises deployment with zero telemetry egress

Agent-specific assurances

  • Graduated autonomy: observe → recommend → act-with-approval → act, set per agent and per parameter
  • Human-in-the-loop approval gates on every validated bonding, lasting and moulding parameter
  • Immutable, quality-grade audit log of every agent action, approval and setpoint write
  • Guardrails and schema validation on tool calls; fail-closed to last known-good recipe
  • Sandboxed factory-edge runtime with signed model artefacts and version rollback
  • Scoped permissions per line, per station and per operator role

Read the security overview →

How your data is handled

The default is that nothing leaves the plant that does not have to.

Edge-first inference

Vision, time-series and process models run on factory-edge hardware. Cloud is for training and fleet management, and is optional.

Tenant isolation

Patterns, lasts, BOMs and telemetry are scoped per tenant and per entity. Nothing is used to train another customer’s models.

Encryption

TLS 1.3 in transit, AES-256 at rest, customer-managed keys available on enterprise agreements.

Retention

Audit and quality records retained for the product-liability window you specify; telemetry retention configurable per plant.

No-egress option

On-premises deployment with zero telemetry egress for brands whose IP cannot leave controlled infrastructure.

Deletion

Documented deletion path for tenant data and derived model artefacts on contract termination.

Every action carries its evidence

A security review usually reduces to one question: can you show me why the machine did that? Here is the answer for the one autonomous decision that paused in RUN-4417.

  1. Action bond.window_control proposed activation 66 °C

    Requested at 10:31:10, approved at 10:34:14 by the shift quality engineer, executed at 10:34:20.

  2. Evidence Sensor readings, datasheet clause and twin prediction attached

    line-b/rh-04 humidity series, adhesive datasheet AD-22 §4.2, twin-predicted bond margin at 64 °C versus 66 °C.

  3. Record Audit trail A-88213, immutable and exportable

    Written to the append-only audit store, signed, and exported nightly to the customer GRC system.

  4. Reversibility Last known-good recipe retained

    If the approval SLA had expired, the agent would have held the previous validated recipe and stopped the affected pairs rather than proceeding.

Why traces matter

Every Footeon decision that touches a cut, a mould, a last or a bond line is recorded as plan, thought, action and observation — with the material lot, sensor reading and spec clause that justified it. Quality engineers can replay any pair.

Traces are retained for the full product-liability window and exported to your MES and quality system.

How the agent runtime is bounded

Four independent mechanisms, so no single failure produces an uncontrolled write.

Before the call

  • Schema and range validation on every tool call
  • Parameter allow-lists per line and station
  • Autonomy level checked per parameter
  • Approval requirement resolved before execution

After the call

  • Outcome verified by vision or metrology
  • Anomalous outcome triggers fail-closed to last known-good
  • Action, evidence and outcome written to the audit log
  • Model regression detection against golden datasets

Who can do what

Roles map to how a plant actually works, not to a generic SaaS permission model.

Default role permissions across autonomy and approvals
RoleView runsChange autonomyApprove validated paramsExport audit
OperatorOwn stationNoNoNo
Line supervisorOwn lineUp to recommendNoNo
Process engineerPlantUp to act-with-approvalMouldingOwn plant
Quality engineerPlantNoBonding, lasting, mouldingOwn plant
Plant managerPlantAll levelsNoOwn plant
Security adminMetadata onlyNoNoAll plants

Security of the models themselves

An autonomy layer is only as safe as the artefacts it runs.

Signed artefacts

Models are signed at build time and signature-verified before the edge runtime loads them.

Evaluation gates

Golden datasets and LLM-as-judge evaluation gate every model and prompt change in CI.

One-command rollback

Any line can be reverted to a previous model version without touching the machine controls.

Sandboxed runtime

The runtime holds only the machine scopes its agents need, enforced outside the model.

Prompt-injection defence

Retrieved documents are treated as data, never as instructions; tool calls are allow-listed.

Drift monitoring

Input and output distributions monitored per line; drift raises an alert before it raises a defect.

Security numbers we hold ourselves to

Targets published so you can hold us to them.

  • 0 customer pattern or last records used to train other tenants’ models
  • 24h target for critical vulnerability triage
  • 7yr default audit-log retention
  • 100% agent outputs carrying a citation or evidence reference

Controls for regulated and brand-audited plants

Everything above, plus the identity, residency and reporting an enterprise risk committee expects.

Identity

  • SAML / OIDC SSO
  • SCIM provisioning
  • Station-level RBAC
  • Break-glass with justification

Residency

  • EU, US or in-country
  • Customer VPC
  • Full on-prem, no egress
  • Air-gapped model updates

Reporting

  • Signed audit exports
  • Approval SLA reporting
  • Model change log
  • Quarterly security review

Security questions

  • Only if you choose. Inference runs on factory-edge servers, and Enterprise deployments can run fully on-premises or in your VPC with no telemetry egress. Brand IP — patterns, lasts, construction specs — is tenant-isolated and never used to train models for another customer.

Send us your security questionnaire

We answer questionnaires, run architecture reviews with your OT team, and support on-prem proofs of concept.