SECURITY

Your formulas
do not
leave.

Serumon writes setpoints into production equipment. That earns a higher bar than normal SaaS: OT-safe integration, no cloud dependency in the control path, per-tenant isolation, formula IP protection and an immutable audit trail your quality team can defend.

ON-PREMOPTION
AES-256AT REST
TLS 1.3IN TRANSIT
SOC 2IN PROGRESS
EVIDENCE PACKSTABION
MICRO RISK · PREDICTED, PASSED STABILITY · NO DRIFT FLAG DEVIATION DRAFT · CITED RELEASE FILE · SIGNED BATCH RELEASED REPLAYABLE · MODEL v4.2.1 · ENVELOPE v11 · APPROVER RECORDED

An auditor gets a replay, not a log file.

ISO 22716 ALIGNEDSOC 2 IN PROGRESSSSO / SAMLRBACSCIMIMMUTABLE AUDITFORMULA IP PROTECTIONAIR-GAP CAPABLE

OT SAFETY

Rules we do not break

NO CLOUD IN CONTROL

Control decisions are made on the plant-edge node. A WAN failure degrades reporting, never control.

  • Local model cache
  • Local state store
  • Reconcile on reconnect

NO SAFETY OVERRIDE

Serumon never writes to safety instrumented systems or interlocks. Your DCS and PLC safety logic stay authoritative.

  • Setpoints only
  • Envelope-clamped
  • Safe-state fallback

SEGMENTED NETWORK

Edge nodes sit in the OT segment with a strictly controlled, one-way-biased path to the IT segment.

  • No inbound from internet
  • Outbound egress policy-gated
  • Broker-mediated

SIGNED ARTEFACTS

Models, envelopes and configuration are signed. Unsigned artefacts do not load, ever.

  • Provenance verified
  • Rollback preserved
  • Version pinned

LEAST PRIVILEGE

Every connector runs with the minimum tag-level permissions needed, documented tag by tag.

  • Read/write split
  • Per-vessel scoping
  • Auditable grants

BREAK-GLASS

Remote support access is customer-approved, time-boxed, session-recorded and revocable at any moment.

  • Explicit approval
  • Full session log
  • Auto-expiry

DATA PROTECTION

Formula IP is the crown jewel

PER-TENANT ISOLATION

Data and model scoping per tenant, with hard isolation between brands inside a contract-manufacturer deployment.

NO CROSS-TENANT TRAINING

Your formulas and shade standards do not train models used for anyone else. Benchmark products require explicit, revocable consent.

ENCRYPTION

TLS 1.3 in transit, AES-256 at rest, with key management aligned to your policy including customer-managed keys where required.

RESIDENCY

Per-region and per-site placement, up to fully on-premise or air-gapped deployments.

RETENTION

Configurable retention per data class, with defensible deletion and export on termination.

PERMISSION-AWARE RETRIEVAL

Vector search filters by permission before ranking, so retrieval cannot leak a document a user could not open.

PLATFORM SECURITY

The usual controls, done properly

SSO + SCIM

SAML and OIDC single sign-on with SCIM provisioning and de-provisioning tied to your directory.

RBAC

Roles mapped to plant reality: operator, process engineer, quality, site admin, group admin — with envelope-change rights separated.

AUDIT LOGGING

Immutable, tamper-evident, exportable to your SIEM and your QMS. Every action carries an actor.

SECURE SDLC

Code review, dependency scanning, secret scanning, infrastructure as code and signed builds through CI.

VULNERABILITY MGMT

Continuous scanning, defined remediation SLAs by severity, and third-party penetration testing.

INCIDENT RESPONSE

Documented runbooks, customer notification commitments and post-incident reports with root cause.

COMPLIANCE

Status, stated honestly

Status, stated honestly
FRAMEWORKSTATUSNOTE
SOC 2 Type IIN PROGRESSTargeted within the first 6 months of the roadmap [ASPIRATIONAL]
SOC 2 Type IIPLANNEDTargeted in the 6–12 month window [ASPIRATIONAL]
ISO 22716 (cosmetics GMP)ALIGNED BY DESIGNSerumon supports your GMP obligations; the certification is the manufacturer’s
GDPRSUPPORTEDDPA available; the platform processes little personal data by design
ISO 27001PLANNEDSequenced after SOC 2 Type II [ASPIRATIONAL]
Penetration testingANNUAL + PRE-MAJOR-RELEASESummary reports available under NDA

SECURITY REVIEW

How we get through your review

  1. 01

    PACK

    Architecture, data-flow diagrams, control matrix and questionnaire responses sent before the first review call.

  2. 02

    ARCHITECTURE CALL

    Our engineers and your IT, OT and security leads walk the deployment, segment by segment.

  3. 03

    VALIDATION PLAN

    A change-control-aligned validation approach for models, envelopes and rollouts agreed in writing.

  4. 04

    CONDITIONS

    Any conditions from review become contractual commitments with owners and dates, not verbal assurances.

AUDIT TRAIL

Designed for the inspector in the room

The question an auditor asks is simple and brutal: show me exactly what this system did to that batch, and who authorised it.

Serumon answers with a replay. Observation, prediction, proposal, confidence, citations, envelope, approver, model version and outcome — for every decision, immutable, exportable, and tied to the batch record.

  • Tamper-evident append-only event log.
  • Model version pinned to every decision.
  • Envelope version pinned to every action.
  • Named approver on every write.
  • Export to your QMS and SIEM.

AUDIT RECORD FIELDS

OBSERVATION
STORED
PREDICTION
STORED
PROPOSAL
STORED
CONFIDENCE
STORED
APPROVER
STORED
MODEL VERSION
PINNED
REPLAYABLE
ALWAYS

COMMITMENTS

What we sign up to

0CROSS-TENANT TRAINING
100%ACTIONS ATTRIBUTED
24HINCIDENT NOTIFICATION TARGET
ANNUALPEN TEST

SECURITY FAQ

What security teams ask

SECURITY

Ask us the hard questions

Request the security pack, or put your security architect in a room with our engineers. We would rather fail your review early than surprise you during rollout.