Security and Governance

Security You Can Inspect

Aktuara is built for plants that cannot let process knowledge, designs, IoT data or camera footage leave their control. Here is what stays, what leaves and how the platform is designed to support the frameworks you work under.

What Stays and What Leaves

Stays in Your Infrastructure

  • All Confidential DataProcess recipes, drawings, IoT and sensor data, camera video, quality and customer records.
  • Prompts, Outputs and LogsEvery question, answer, source and approval, stored in your account.
  • Models and Knowledge BaseYour fine-tuned models, embeddings, ratings and settings, which stay yours if you leave.

Leaves, Only If You Allow It

  • Operational Health MetricsCPU, GPU, memory and error rates, so we can operate the platform. Inspectable and switchable.
  • Public-Only Tasks for Managed AIMarket news, supplier filings and public regulation, under a monthly cap. Can be switched off entirely.

Frameworks and the Controls Behind Them

How Aktuara is designed to support the rules manufacturers work under.

FrameworkWhat It AsksHow Aktuara Is Designed to Support It
GDPRLawful, minimal processing of personal data, including worker data in logs and video.Processing only in your infrastructure; role-based access; configurable retention; face blurring at the source for video; documentation for your DPIA.
EU AI ActTransparency, human oversight and logging for AI systems; prohibited practices such as emotion recognition at work.Human review of every output; full request and approval logs; no emotion recognition, no facial recognition, no individual worker scoring.
NIS2Risk management and incident handling for essential and important entities.Hardened, monitored platform; security patching operated for you; incident notification commitments in the contract.
IEC 62443Security for industrial automation and control systems, including zones and conduits.Read-only connectors; deployment inside the zones you define; no inbound access to control networks; edge servers under your network policy.
ISO/IEC 27001An information security management system with defined controls.Encryption in transit and at rest, access reviews, audit trails and change management that fit your existing ISMS controls.
ISO 9001 and IATF 16949Controlled documents, traceability and change control in quality management.Answers cite document versions; configuration changes are versioned, tested and approved before release.
EU Data ActAccess to and sharing of data generated by connected products.IoT data stays in your infrastructure, under your control, with export in open formats.
Export control (EU dual-use, US EAR)Restrictions on transferring controlled technical data.Controlled designs never leave your chosen region or reach a managed model; the policy check can block tagged documents entirely.

Designed to support, not a certification. Compliance depends on how your organisation deploys and uses the platform. Aktuara is decision support and is not intended as a safety function under the EU Machinery Regulation.

Questions from IT, OT Security and Quality Teams

What exactly leaves our account?

Process, design, IoT, video, quality and customer data never leave, including prompts, outputs, documents and logs. Operational health metrics leave only if you allow them, and you can inspect or switch them off. Managed AI receives only public-only tasks you route to it, under a monthly cap.

Can your staff see our data?

No. We operate the platform through infrastructure automation and health metrics, without access to your documents, prompts, outputs or video. Any support access is requested, time-limited, approved by you and logged.

Does Aktuara connect to our OT network?

Only read-only and only where you decide. Connectors to historians, OPC UA and MQTT are deployed inside the network zones you define. Aktuara never writes to PLCs, robots or production systems.

Is Aktuara certified under these frameworks?

Aktuara is designed to support the frameworks listed on this page and provides documentation for your assessments. Compliance depends on how your organisation deploys and uses the platform, so it is not a substitute for your own assessment or certification.

Where is our data stored?

In your own cloud account in the region you choose, in Europe or North America, in your data centre, or on edge servers at your plant.

Request the Security Documentation

We will share the architecture, data-flow and security overview with your CISO, OT security and quality teams before any pilot starts.