Skip to content

Security

How does Qynetic protect customer data and machines?

Security and industrial safety are foundational to Qynetic's design. Tenant isolation is enforced in the database with Row Level Security, permissions are capability-based, audit history is immutable, administrators use multi-factor authentication, and AI is never allowed to directly control machinery.

  • Tenant isolation

    Every tenant-owned record carries its organisation, and the database enforces isolation with Row Level Security — frontend filtering is never relied on. Foreign keys are composite, so a record cannot reference another organisation's site. Isolation is tested automatically against the real database schema, including attempts to read and write across tenants.

  • Capability-based access

    Access is granted through capabilities such as quality.view or apc.approve, bundled into roles and scoped to an organisation or a single site.

    • Organisation admin, site admin, engineer, quality engineer, production planner, maintenance, operator, viewer
    • A site-scoped role never grants organisation-level access
    • Module access is licensed per organisation and permitted per user
  • Audit and immutability

    Events, audit records and approvals are append-only: the database rejects updates and deletes. Every significant action is attributable to a human, system, agent or integration.

  • Administrator access

    Customer provisioning is done from a separate administration application. It requires a verified identity, an allow-listed administrator account and a TOTP-verified session. Every change is made through audited database functions that only that application can run.

  • Secrets

    Integration credentials are never stored in configuration or exposed to the browser; configuration holds only a reference to a secret store. The all-powerful database key is held only by the administration application and a single server-side function.

  • AI and machine control

    AI may reason; it must not directly control physical machinery. Adjustments pass through a validated algorithm, simulation, a deterministic guardian and deterministic control. Anything outside authorised limits requires human approval, and values outside absolute bounds are rejected and cannot be approved.

  • Resilience

    Safety-relevant control is designed to run near the machine so that loss of cloud connectivity cannot cause unsafe behaviour.

  • Data location

    The database is hosted in the EU (Stockholm).

What we do not claim

Qynetic is in early development. We make no claims about third-party certifications or audits, and this page describes design principles and implemented foundations rather than guarantees.

Be among the first to know

Qynetic is being built now. Join the waitlist and we will tell you when it is available.

We store the details you provide only to contact you about Qynetic.