Per-tenant isolation
Data, models and memory are scoped and isolated per tenant with no cross-tenant leakage.
Trust & security
Foldeon controls real machines, brand artwork and proprietary recipes. Trust is architected in, grounded outputs, bounded control, per-tenant isolation and an immutable audit log for every agent action.
The stance
What keeps a plant, its brands and its recipes safe.
Data, models and memory are scoped and isolated per tenant with no cross-tenant leakage.
Strict protection of intellectual property, brand artwork and process recipes throughout.
A quality-grade, immutable audit trail records every agent action and control move.
Sensitive converters can run fully on-prem while keeping the same guarantees.
Grounded by design
Citation and grounding checks run on every output, and RAG retrieval is multi-tenant isolated, permission-aware and citation-enforcing, so quality and engineering can trace why any move was made.
Bounded control
Automatic changes are limited to qualified job families with hard ranges, PLC permissions, model-version gates and quality holds. Higher-risk changes require human approval.
Evaluation & change control
Continuous evaluation against golden datasets gates every model and prompt change in CI.
Automated judging supplements golden sets to catch regressions before release.
Safety and schema guardrails constrain every agent action.
Every model version and setpoint change is recorded with rollback evidence.
Compliance
| Item | Status |
|---|---|
| SOC 2 Type I | In progress (design-partner phase) |
| SOC 2 Type II | Planned (6–12 month roadmap) |
| SSO / RBAC | Planned with enterprise tier |
| Per-tenant isolation | Built-in |
| On-prem deployment | Available for sensitive converters |
| Immutable audit log | Built-in |
On a plant floor, an unexplained automatic move is worse than no move at all. Everything Foldeon does is bounded, grounded and logged.
Answers
You choose. Foldeon runs at the plant edge and private cloud, with an optional fully on-prem deployment for sensitive converters. Data, models and memory are tenant-isolated wherever they run.
Only within hard, pre-qualified ranges for low-risk job families, gated by PLC permissions, model versions and quality holds. Anything higher-risk requires human approval.
Artwork, IP and recipes are strictly protected and tenant-scoped, and synthetic data generation avoids exposing any customer’s proprietary content.
SOC 2 Type I is in progress during the design-partner phase, with Type II planned on the 6–12 month roadmap alongside SSO/RBAC.
We’ll walk your IT/OT, quality and security teams through the architecture and controls.