Works from CSV or workbook exports produced from SAP, IBM Maximo, Oracle ERP, Hexagon EAM, Infor, and other ERP, EAM, or CMMS systems. No direct integration or write-back is required — Review data requirements →
Trust Center

Industrial IQ Trust Center for security and governance review.

A buyer should not need a sales call to understand how the portal protects identity, reports, admin activity, uploaded diagnostics, and decision governance.

Owner-onlyAdmin access
AuditableBefore/after change ledger
No write-backDiagnostic-only ERP posture
Executive AI governance layer showing risk controls, evidence records, approval checkpoints, and audit-ready decision support.
Trust controls make source traceability, confidence tiering, human review, and auditability visible before remediation decisions.
Evidence summary

Trust and governance guide

AI2COE Trust Center: The Trust Center explains the control posture behind Industrial IQ so enterprise buyers can inspect data handling, review boundaries, and evidence discipline before adoption. Review AI2COE's diagnostic safety model for source handling, no ERP write-back, human review, confidence tiers, report ownership, and audit controls.

Review Trust Controls
Review ownerCISO, CIO, legal, procurement, governance, data owners, and executive sponsors evaluating diagnostic boundaries
Input file contextUpload lifecycle, authentication, retained metadata, report ownership, audit events, policy documents, and data-handling commitments.
Diagnostic evidenceA trust view of no ERP write-back, human review, confidence tiers, source-data handling, report ownership, and governance limits.
Recommended actionReview the controls, then use Snapshot or sample reports to inspect the evidence model before private upload.
Enterprise trust posture

Proof controls buyers expect before they upload operational data.

Source purge Uploaded source files are purged after report generation; summary metrics and Open Findings remain.
No ERP write-back The diagnostic creates evidence for review. It never changes, deletes, merges, or overwrites ERP records.
Local currency Reports display money in the user's selected or country-derived currency, while USD remains the base audit calculation.
Audit trail Report ownership, access, quota, and feedback events are retained for governed review.
Session downloads Excel, Word, PDF, and CSV downloads are available only in the active generation session.
Open Findings Browser findings remain available without retaining the original source catalog rows.
Data lifecycle visual

Uploaded data moves through a controlled diagnostic lifecycle.

This visual summarizes the buyer-safe operating model. The detailed control catalogue and policy links remain below for security, legal, and procurement review.

Review Data Retention
01 Uploaded source file CSV or workbook export enters the governed diagnostic path.
02 Diagnostic processing Industrial IQ maps fields, validates source fit, and runs the selected engine.
03 Report generation Evidence, scores, confidence tiers, limitations, and owner actions are packaged.
04 Source-file purge Source files are purged after report generation according to disclosed handling boundaries.
05 Governance metadata Open Findings, summary metrics, report ownership, continuity metadata, and audit events may be retained where required.
Visual control matrix

Security and procurement reviewers should see the trust boundary at a glance.

Icons are paired with visible labels and status tags. They summarize the control posture without replacing the detailed policy text below.

Open Security Brief
Live

No ERP write-back

Diagnostics do not autonomously change SAP, Maximo, Oracle, EAM, CMMS, procurement, or inventory systems.

Live

Read-only workflow

Industrial IQ evaluates exported operational data and produces review evidence before any buyer-controlled remediation.

Live

Source-file purge

Uploaded source files are used to generate report packs and are purged after report generation according to disclosed handling boundaries.

Live

Human review

Confidence tiers and review queues separate evidence-ready findings from owner-review candidates.

Live

Confidence tiers

Findings carry confidence context so buyers can distinguish strong evidence from review-required signals.

Live

Audit metadata

Open Findings, report ownership, continuity metadata, and audit events support governance where required.

Published

DPA / SLA path

DPA, engagement SLA, security overview, and procurement review language are available for buyer review.

Roadmap

SOC 2 boundary

AI2COE does not claim SOC 2 Type II certification; audit maturity remains a roadmap item until completed.

Executive trust thesis

AI2COE is designed to produce evidence without creating operational risk.

Industrial AI adoption fails when a platform asks for trust before producing evidence. AI2COE reverses the order: upload an operational export, generate a controlled diagnostic, review confidence-tiered findings, and decide whether remediation is worth funding.

The portal deliberately avoids automatic ERP write-back. This matters across every engine: catalog review, inventory policy, procurement leakage, working-capital interpretation, asset-to-part linkage, maintenance readiness, AI readiness, and evidence governance all require source-backed review before action.

Pilot availability: AI2COE accepts structured enterprise pilots. Contact for scoped engagement terms.
Controls already implemented
Email verificationProtected workflows require verified identity
Admin change ledgerBefore/after records for admin edits
Report ownershipOpen Findings tied to authenticated users; downloads are session-scoped
Source purgeUploaded operational source files are purged after report generation where session-scoped handling applies
Security headersFrame, MIME, referrer, permission, and production HSTS controls
Diagnostic data lifecycle

Evidence without uncontrolled source-data retention.

1Upload export
2Run selected engine
3Generate reports
4Purge source file
5Retain Open Findings and summary metrics
What AI2COE never does

Diagnostic evidence is not uncontrolled remediation.

This boundary is intentionally visible for CIO, CISO, procurement, and operations reviewers.

Does not overwrite ERP records
Does not autonomously merge or delete records
Does not replace master-data approval
Does not request private data in public contact forms
Does not promise financial outcomes
Does not replace procurement, maintenance, finance, or engineering judgment
Control catalogue

What the CTO, CIO, CISO, CRO, and procurement team should see.

Identity & Access

Identity & Access

Email verification gate, complete business profile, locked identity fields, current-password update checks, owner-only admin authorization, and session-based access control.

Report Governance

Report Governance

Report ownership records, expiring report links, persistent in-browser Open Findings, immediate-session artifact downloads, and generated-by attribution on report artifacts.

Diagnostic Safety

Diagnostic Safety

No ERP write-back. Confidence tiers separate evidence-ready findings from review candidates. Engine-specific controls reduce unsafe catalog, inventory, procurement, finance, asset, reliability, readiness, and governance recommendations.

Admin Auditability

Admin Auditability

Admin dashboard views, exports, edit-page access, and updates are logged. User and lead edits write before/after JSON to the admin change ledger.

Browser Security

Browser Security

CSRF protection, HTTP-only sessions, SameSite cookies, X-Frame-Options, nosniff, referrer policy, and production-ready HSTS activation.

Data Handling

Data Handling

CSV diagnostic input is processed through isolated run folders and the uploaded source file is purged after report generation. Excel, Word, PDF, and CSV downloads are available only in the active generation session. AI2COE retains Open Findings, summary metrics, report ownership, quota usage, feedback, and audit metadata only.

Data Residency

Data Residency

AI2COE diagnostic processing is currently hosted in the United States (primary). European Union accounts requiring in-region data processing and a GDPR Article 28 DPA should contact support@ai2coe.com with 'DPA Request' in the subject. Gulf Cooperation Council (GCC) accounts may request a data-handling commitment specific to their jurisdiction. In-region EU and GCC hosting is on the enterprise roadmap. Custom data residency arrangements are available by agreement for enterprise pilot accounts.

Current controls vs roadmap

What is available now, what is published for review, and what remains roadmap.

AI2COE is designed for low-risk diagnostic evaluation: exported data, no production-system write-back, source-file purge after report generation, evidence traceability, confidence tiers, and human review. The table below separates implemented controls from future maturity items so security and procurement teams can review the boundary without overclaiming.

Control areaCurrent statusEvidence availableRoadmap / next maturity step
No ERP write-backLiveTrust Center, upload workflow language, no-write-back pageContinue buyer-specific architecture review during enterprise pilots.
Read-only diagnostic workflowLiveExport-first upload path and engine pagesExpand lightweight health and route monitoring around diagnostic workflows.
Source-file purge after report generationLive for disclosed diagnostic flowsData Handling Commitment and Data Retention pagesContinue retention automation and buyer-specific DPA review where required.
Open Findings retentionLiveAuthenticated Open Findings and report ownership recordsClarify retention limits in customer-specific engagement terms.
Summary metrics and audit metadataLiveAdmin auditability, usage, report ownership, and governance metadataExpand procurement-ready audit export coverage as enterprise pilots mature.
Human review and confidence tiersLiveEngine pages, sample reports, and methodology pagesIncrease owner-review workflow depth for multi-site programs.
DPA and SLAPublishedDPA template and Engagement SLA pagesCountersigned versions available during scoped buyer review.
Security overview and architecturePublishedSecurity Overview, Architecture, BC/DR, Procurement FAQMaintain security questionnaire response pack for enterprise reviews.
SOC 2 self-attestationPublished bridge documentManagement self-attestation pageDoes not replace independent SOC 2 Type I or Type II audit.
SOC 2 Type IIRoadmap / not certifiedExplicit Trust Center boundaryFormal audit remains roadmap; do not claim certification until complete.
Data residencyCurrent primary hosting disclosedTrust Center and Data Handling pagesEU/GCC in-region hosting remains enterprise roadmap or custom agreement topic.
Role-based access controlsFounder/admin and authenticated user controls liveOwner-only admin authorization and report ownership modelExpanded RBAC remains a future enterprise hardening step.
Industrial IQ platform architecture

Eight diagnostic engines create the Industrial IQ platform.

Catalog Intelligence

PartsCleanse AI

MRO catalog deduplication, field quality, UOM consistency, and duplicate capital exposure.

View engine
Inventory Risk Intelligence

InventoryMind AI

Dead stock, slow-moving stock, excess, stockout risk, and duplicated stock exposure.

View engine
Procurement Leakage Intelligence

ProcureMind AI

Emergency procurement, stocked-but-purchased events, repeated buys, supplier alias risk, and price variance.

View engine
Working Capital Intelligence

FinanceMind AI

Duplicate capital exposure, carrying cost, emergency premium, and recoverable value scenarios.

View engine
Asset-to-Part Intelligence

AssetMind AI

Asset-to-part linkage, critical spare coverage, obsolete asset spares, and plant risk heatmaps.

View engine
Maintenance Readiness Intelligence

ReliabilityMind AI

Work-order spare availability, false stockout risk, repeat demand, and shutdown readiness.

View engine
AI Readiness Intelligence

ReadyMind AI

ERP data quality, governance readiness, operational readiness, and first-use-case recommendation.

View engine
Evidence Governance Intelligence

GovernanceMind AI

Evidence traceability, review-level assignment, owner approval, auditability, and no-write-back governance.

View engine
Deployment readiness

Honest launch-readiness classification.

Launch stageStatusInterpretation
Pilot / demoReadyLocal and controlled founder-led pilots; authenticated uploads; report generation; admin audit layer.
Paid founder-led pilotReady with controlsAppropriate for selected customers after NDA, data-handling commitment, and manual onboarding.
Public self-serve launchNear-readyNeeds production domain config, SMTP, OAuth credentials, HTTPS, backups, retention automation, and monitoring.
Large enterprise procurementNear-readyDPA template, Engagement SLA, Data Handling Commitment, Security Overview, SOC 2 self-attestation, and Procurement FAQ now published. Remaining: SOC 2 Type II audit, production cloud hardening, uptime monitoring.
Policy and document library

All compliance documents in one place.

DocumentPurposeAudienceStatus
Data Handling CommitmentWhat happens to uploaded catalog CSV files — purge commitmentLegal, CISO, ProcurementPublished
Data Processing Agreement (DPA)GDPR Article 28 DPA template for countersignatureLegal, EU/UK/GCC accountsPublished
Engagement SLA15-business-day delivery commitment and overrun remedyProcurement, FinancePublished
Security OverviewEncryption, access controls, data residency, incident responseCISO, Security teamPublished
SOC 2 Self-AttestationCEO attestation of SOC 2 Trust Service Criteria controlsEnterprise procurementPublished
Architecture OverviewData flow diagram, isolation boundaries, purge pathwayCTO, Security architectPublished
Procurement FAQW-9, insurance, payment terms, contract vehicle answersProcurement, SourcingPublished
Refund & Cancellation PolicyMilestone-based refund schedule and SLA overrun remedyFinance, ProcurementPublished
Getting Started GuideCSV format specs, engagement process, report deliverablesIT, Operations leadPublished
Acceptable Use PolicyPermitted and prohibited uses of the portalLegal, ITPublished
BC/DR SummaryRecovery objectives, backup strategy, incident communicationCISO, Enterprise procurementPublished
Release NotesProduct changelog and version historyTechnical evaluatorsPublished
SOC 2 Type II ReportIndependent auditor's examination of security controlsEnterprise procurementPlanned — 12-18 months
Enterprise FAQ

Questions a buyer, CIO, or CISO will ask first.

Does AI2COE write back to SAP, Maximo, Oracle, or any ERP?

No. Industrial IQ is diagnostic-first. It analyzes uploaded operational exports and produces evidence for review. No automatic ERP record changes, deletions, merges, policy updates, or write-back actions are performed by any engine.

How is report access controlled?

Reports are tied to the logged-in user who generated them. Report links expire by default, downloads require authentication, and owner-admin access is restricted to the founder account.

What protects account and profile integrity?

New accounts require profile completion, explicit consent, and email verification before protected workflows are available. Important identity fields are locked, while editable profile updates require authentication.

What can be audited?

Admin views, exports, report access, downloads, profile changes, and admin edits are written to audit logs. Admin edits also preserve before/after values in a separate change ledger.

Has AI2COE completed SOC 2 Type II certification?

No. AI2COE is pilot-ready and has not completed SOC 2 Type II certification yet. The Trust Center separates controls already implemented from controls required before broad enterprise production hosting.

Buyer intent

What decision this page helps the buyer make.

Decision question

Can Industrial IQ produce diagnostic evidence without uncontrolled system change or unclear data handling?

Best-fit reader

CIO, CISO, legal, procurement, and governance reviewers checking boundaries before upload.

Related decision topics
no ERP write-backread-only ERP diagnostichuman reviewdata controls
Useful next reads
Buyer journey

Choose the next action by buyer readiness.

Choose the next action based on where the buying committee is now: proof review, data readiness, pilot scoping, or security validation.

Open evaluation guide

Trust boundary: No ERP write-back. Source files purged after report generation. Human review before action. Sample reports use demonstration data until replaced by uploaded-data diagnostics.

Branded visual operating model

Trust should show the control boundary visually.

The review path makes source exports, confidence tiers, human review, and no ERP write-back clear before data is uploaded.

View workflow
Branded industrial operations visual showing plant assets, stores, maintenance context, and Industrial IQ diagnostic overlay.
Industrial context Start from real operating context

MRO stores, assets, maintenance, procurement, and site context are shown as the operating layer behind every diagnostic.

Branded source export visual showing ERP, EAM, CMMS, inventory, procurement, asset, and work-order data flowing into Industrial IQ.
Source exports Use exported operational data

Industrial IQ starts with CSV or workbook exports, field mapping, and source-fit review before findings are treated as evidence.

Branded evidence review visual showing confidence tiers, source rows, matched records, reason codes, and reviewer status.
Evidence review Make the finding inspectable

Findings show source evidence, confidence, reason codes, assumptions, limitations, and human-review status.

Branded governed action tracker visual showing owners, status, due date, confidence, and no ERP write-back boundary.
Governed action Move only after owner review

Actions are accepted, rejected, deferred, or escalated by accountable owners. No ERP write-back happens automatically.

Trust review lens

Use this page to validate the operating boundary before data is uploaded.

Trust review gives security, procurement, legal, IT, and governance reviewers clear language before a diagnostic starts.

Best-fit reader

CISO, CIO, procurement, legal, risk, security, data governance, and enterprise architecture teams.

Evidence to prepare

Hosting, access, data handling, retention, source-file purge, no ERP write-back, human review, DPA, SLA, and buyer-security review language.

Output to expect

A buyer-security review path that clarifies what Industrial IQ does, what it does not do, and what can be reviewed during procurement.

Trust boundary

Read-only diagnostics, no ERP write-back, source-file purge after report generation, and human review before action.

AI2COE Copilot