Works from CSV or workbook exports produced from SAP, IBM Maximo, Oracle ERP, Hexagon EAM, Infor, and other ERP, EAM, or CMMS systems. No direct integration or write-back is required — Review data requirements →
Security Overview

Technical and organizational security controls for the AI2COE platform.

For CISOs, security teams, and enterprise procurement teams completing vendor security assessments. Covers encryption, access control, catalog data isolation, incident response, and current audit status.

TLS 1.2+All connections
Catalog purgePost-processing
72-hourBreach notification
Executive AI governance layer showing risk controls, evidence records, approval checkpoints, and audit-ready decision support.
Trust controls make source traceability, confidence tiering, human review, and auditability visible before remediation decisions.
Security controls

Technical and organizational measures in production.

Encryption in transit

All data transmitted between client browsers and the AI2COE portal uses TLS 1.2 as the minimum protocol. HSTS is configured for production deployments to enforce HTTPS for all connections.

Encryption at rest

Application database is encrypted at the storage layer in production. Diagnostic run folders containing report artifacts are stored on encrypted volumes.

Access control — application layer

Administrative pages are protected by session authentication and owner-authorization checks. Report artifacts are tied to authenticated user accounts. Report link expiry controls are implemented.

Access control — infrastructure layer

Production server access is restricted to authorized administrators via SSH key authentication. Password authentication for server access is disabled in production.

Catalog data isolation

Each diagnostic run executes in an isolated session folder. Source files are purged after report generation. Summary metrics, Open Findings, report ownership, quota usage, feedback, and audit metadata may be retained for governance.

Security headers

X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, Content-Security-Policy, and HSTS headers configured on all responses.

Session management

HTTP-only, SameSite=Lax session cookies. CSRF tokens required for all state-changing form submissions. Sessions invalidated on logout.

Incident response

Material security incidents affecting client data are notified to affected clients without undue delay and within 72 hours of discovery, consistent with GDPR Article 33 processor obligations.

Audit and certification status

Current compliance posture — honest disclosure.

ProgramStatus
Penetration testingScheduled — not yet completed for production environment. Will be performed before broad public launch.
SOC 2 Type IIPlanned. Self-attestation letter available at /soc2-attestation. Formal audit timeline: 12-18 months post public launch.
ISO 27001Not currently certified. Controls aligned with ISO 27001 Annex A requirements for access control, cryptography, and incident management.
GDPR complianceDPA template available at /dpa. EU/UK data transfer mechanisms available on request. Processing occurs in the United States.
Vulnerability disclosureContact support@ai2coe.com with subject 'Security Disclosure'. Acknowledged within 2 business days.
Quotable control — encryption standard

All data in transit is protected by TLS 1.2 or higher. Catalog data and report artifacts stored at rest are encrypted with AES-256. Session run folders are isolated per upload and purged automatically after report generation completes.

Quotable commitment — breach notification

Industrial IQ commits to notifying affected clients within 72 hours of confirming a material data breach, consistent with GDPR Article 33 processor obligations. Notification includes breach nature, data categories affected, estimated record count, and remediation actions taken.

Control boundary

Review the operating controls in one consistent visual language.

Trust pages separate read-only diagnostics, data handling, confidence, human review, and procurement controls without turning policy into marketing.

Open Trust Center
Trust review lens

Use this page to validate the operating boundary before data is uploaded.

Trust review gives security, procurement, legal, IT, and governance reviewers clear language before a diagnostic starts.

Audience

CISO, CIO, procurement, legal, risk, security, data governance, and enterprise architecture teams.

Evidence to prepare

Hosting, access, data handling, retention, source-file purge, no ERP write-back, human review, DPA, SLA, and buyer-security review language.

Output

A buyer-security review path that clarifies what Industrial IQ does, what it does not do, and what can be reviewed during procurement.

Trust boundary

Read-only diagnostics, no ERP write-back, source-file purge after report generation, and human review before action.

AI2COE Copilot