Trust & security

Autonomy you can audit, line by line

Foldeon controls real machines, brand artwork and proprietary recipes. Trust is architected in, grounded outputs, bounded control, per-tenant isolation and an immutable audit log for every agent action.

The stance

The security posture

What keeps a plant, its brands and its recipes safe.

Per-tenant isolation

Data, models and memory are scoped and isolated per tenant with no cross-tenant leakage.

IP & artwork protection

Strict protection of intellectual property, brand artwork and process recipes throughout.

Immutable audit log

A quality-grade, immutable audit trail records every agent action and control move.

Optional on-prem

Sensitive converters can run fully on-prem while keeping the same guarantees.

Grounded by design

Every output is traceable to a source

Citation and grounding checks run on every output, and RAG retrieval is multi-tenant isolated, permission-aware and citation-enforcing, so quality and engineering can trace why any move was made.

  • Citation/grounding checks on every output
  • Permission-aware, citation-enforced RAG
  • Root-cause explanations tied to real telemetry
  • No unexplained black-box moves
Decision · loggedAUTONOMOUS
Grounded✓ cited
Approvaloperator
Rollbackrecorded
Tenantisolated
Auditabilityon target

Bounded control

Machines move only within limits you set

Automatic changes are limited to qualified job families with hard ranges, PLC permissions, model-version gates and quality holds. Higher-risk changes require human approval.

  • Hard setpoint ranges and PLC permissions
  • Model-version gates before any write-back
  • Quality holds that stop the line on risk
  • Human-in-the-loop for high-risk changes

Evaluation & change control

Nothing ships to a plant untested

Golden datasets

Continuous evaluation against golden datasets gates every model and prompt change in CI.

LLM-as-judge

Automated judging supplements golden sets to catch regressions before release.

Guardrails

Safety and schema guardrails constrain every agent action.

Versioned rollback

Every model version and setpoint change is recorded with rollback evidence.

Compliance

Program status

ItemStatus
SOC 2 Type IIn progress (design-partner phase)
SOC 2 Type IIPlanned (6–12 month roadmap)
SSO / RBACPlanned with enterprise tier
Per-tenant isolationBuilt-in
On-prem deploymentAvailable for sensitive converters
Immutable audit logBuilt-in
100%Tenant isolation
Every oneActions audited
GraduatedHITL checkpoints
YesOn-prem option
On a plant floor, an unexplained automatic move is worse than no move at all. Everything Foldeon does is bounded, grounded and logged.
Head of Trust & SafetyFoldeon

Answers

Questions converters ask

Where does our data live?

You choose. Foldeon runs at the plant edge and private cloud, with an optional fully on-prem deployment for sensitive converters. Data, models and memory are tenant-isolated wherever they run.

Can Foldeon change a machine without approval?

Only within hard, pre-qualified ranges for low-risk job families, gated by PLC permissions, model versions and quality holds. Anything higher-risk requires human approval.

How is our brand artwork protected?

Artwork, IP and recipes are strictly protected and tenant-scoped, and synthetic data generation avoids exposing any customer’s proprietary content.

Do you have SOC 2?

SOC 2 Type I is in progress during the design-partner phase, with Type II planned on the 6–12 month roadmap alongside SSO/RBAC.

Review our security in depth

We’ll walk your IT/OT, quality and security teams through the architecture and controls.