PER-TENANT ISOLATION
Data and model scoping per tenant, with hard isolation between brands inside a contract-manufacturer deployment.
SECURITY
Serumon writes setpoints into production equipment. That earns a higher bar than normal SaaS: OT-safe integration, no cloud dependency in the control path, per-tenant isolation, formula IP protection and an immutable audit trail your quality team can defend.
An auditor gets a replay, not a log file.
OT SAFETY
Control decisions are made on the plant-edge node. A WAN failure degrades reporting, never control.
Serumon never writes to safety instrumented systems or interlocks. Your DCS and PLC safety logic stay authoritative.
Edge nodes sit in the OT segment with a strictly controlled, one-way-biased path to the IT segment.
Models, envelopes and configuration are signed. Unsigned artefacts do not load, ever.
Every connector runs with the minimum tag-level permissions needed, documented tag by tag.
Remote support access is customer-approved, time-boxed, session-recorded and revocable at any moment.
DATA PROTECTION
Data and model scoping per tenant, with hard isolation between brands inside a contract-manufacturer deployment.
Your formulas and shade standards do not train models used for anyone else. Benchmark products require explicit, revocable consent.
TLS 1.3 in transit, AES-256 at rest, with key management aligned to your policy including customer-managed keys where required.
Per-region and per-site placement, up to fully on-premise or air-gapped deployments.
Configurable retention per data class, with defensible deletion and export on termination.
Vector search filters by permission before ranking, so retrieval cannot leak a document a user could not open.
PLATFORM SECURITY
SAML and OIDC single sign-on with SCIM provisioning and de-provisioning tied to your directory.
Roles mapped to plant reality: operator, process engineer, quality, site admin, group admin — with envelope-change rights separated.
Immutable, tamper-evident, exportable to your SIEM and your QMS. Every action carries an actor.
Code review, dependency scanning, secret scanning, infrastructure as code and signed builds through CI.
Continuous scanning, defined remediation SLAs by severity, and third-party penetration testing.
Documented runbooks, customer notification commitments and post-incident reports with root cause.
COMPLIANCE
| FRAMEWORK | STATUS | NOTE |
|---|---|---|
| SOC 2 Type I | IN PROGRESS | Targeted within the first 6 months of the roadmap [ASPIRATIONAL] |
| SOC 2 Type II | PLANNED | Targeted in the 6–12 month window [ASPIRATIONAL] |
| ISO 22716 (cosmetics GMP) | ALIGNED BY DESIGN | Serumon supports your GMP obligations; the certification is the manufacturer’s |
| GDPR | SUPPORTED | DPA available; the platform processes little personal data by design |
| ISO 27001 | PLANNED | Sequenced after SOC 2 Type II [ASPIRATIONAL] |
| Penetration testing | ANNUAL + PRE-MAJOR-RELEASE | Summary reports available under NDA |
SECURITY REVIEW
Architecture, data-flow diagrams, control matrix and questionnaire responses sent before the first review call.
Our engineers and your IT, OT and security leads walk the deployment, segment by segment.
A change-control-aligned validation approach for models, envelopes and rollouts agreed in writing.
Any conditions from review become contractual commitments with owners and dates, not verbal assurances.
AUDIT TRAIL
The question an auditor asks is simple and brutal: show me exactly what this system did to that batch, and who authorised it.
Serumon answers with a replay. Observation, prediction, proposal, confidence, citations, envelope, approver, model version and outcome — for every decision, immutable, exportable, and tied to the batch record.
AUDIT RECORD FIELDS
COMMITMENTS
SECURITY FAQ
No. The edge node initiates outbound connections through a policy-gated path, and support access is broker-mediated and customer-approved. Air-gapped deployments have no uplink at all.
In a standard deployment: telemetry and model-performance metrics, scoped by policy. Formula definitions, shade standards and batch records can be excluded entirely. In on-prem mode nothing leaves.
Nodes fail to a safe state and lose actuation rights on revocation. Signed-artefact loading, per-vessel credential scoping and immutable logging limit blast radius, and the incident runbook includes customer notification commitments.
Yes, customer-managed keys are supported for enterprise deployments. Key rotation and revocation procedures are agreed during the security review.
SECURITY
Request the security pack, or put your security architect in a room with our engineers. We would rather fail your review early than surprise you during rollout.