How does Qynetic protect customer data and machines?
Security and industrial safety are foundational to Qynetic's design rather than add-ons. This page describes the design principles; it makes no claims about third-party certifications.
Tenant isolation
Every tenant-owned record carries its organisation, and the database enforces isolation with Row Level Security. Foreign keys are composite so a record cannot reference another organisation's site. Isolation is tested automatically against the real schema.
Capability-based access
Access is granted through capabilities such as quality.view or apc.approve, bundled into roles (organisation admin, site admin, engineer, quality engineer, production planner, maintenance, operator, viewer) and scoped to an organisation or a single site.
Audit and immutability
Events, audit records and approvals are append-only; the database rejects updates and deletes. Every significant action is attributable to a human, system, agent or integration.
Secrets
Integration credentials are never stored in configuration or exposed to the browser; configuration holds only a reference to a secret store.
AI and machine control
AI may reason; it must not directly control physical machinery. Adjustments pass through a validated algorithm, simulation, a deterministic guardian and deterministic control. Anything outside authorised limits requires human approval, and values outside absolute bounds are rejected and cannot be approved.
Resilience
Safety-relevant control is designed to run near the machine so that loss of cloud connectivity cannot cause unsafe behaviour.