SECURITY & DATA
Your production data belongs to you, and stays where you put it
Production data is commercially sensitive. It shows what you make, how fast, how well, for whom, and where you struggle. It is also increasingly subject to regulation about where it may be processed and who may reach it. A great many industrial software products answer these questions by saying "trust us, it's in our cloud." Our answer is simpler: the system runs on your infrastructure, the data stays there, and we hold no copy of it.
How data is handled
It stays on your servers
The database sits on infrastructure you control, on-premise or in your own EU-hosted environment. We do not operate a central service that your production data is sent to.
Inside the EU
Hosted deployments use European data centres. As an EU company working with EU manufacturers, data residency is the default rather than a premium option.
Read-only at the control layer
Acquisition reads from your controllers and does not write to them. The MES cannot change what a machine does, which keeps it out of the safety and control path entirely.
Role-based access
Operators, supervisors, quality staff and management see what their role requires. Access is configured to your organisation rather than assumed.
Maintained and patched
Operating system and database security patching is part of the service, not something left for a plant IT function to remember. An unpatched production server is the realistic risk, not an exotic attack.
Backed up and restorable
Regular backups with restore actually tested — because a backup nobody has restored is an assumption, not a safeguard.
Working with your IT function
We meet your standards, not ours
Network segmentation, access paths, remote support arrangements and authentication are agreed with your IT team during scoping and documented before installation.
Remote access on your terms
Support requires some access to the system. How that works — VPN, jump host, scheduled sessions, whatever your policy requires — is your decision, and we work within it.
Documented for review
You get a written description of the architecture, data flows and access arrangements, in a form your IT function or an auditor can review.
GDPR and data protection
Production data is largely machine data, but an MES will usually process some personal data — which operator was on shift, who entered a measurement, who logged in. Where we process personal data on your behalf, the arrangement is set out in a data processing agreement alongside the service contract, with the roles, purposes and retention periods defined. Because the data remains on your infrastructure within the EU, the cross-border transfer questions that complicate non-EU services do not arise.
BRING YOUR IT TEAM INTO THE CONVERSATION
We are happy to go through architecture, access and data handling with whoever has to approve it.