Works from CSV or workbook exports produced from SAP, IBM Maximo, Oracle ERP, Hexagon EAM, Infor, and other ERP, EAM, or CMMS systems. No direct integration or write-back is required — Review data requirements →
Trust Center

Industrial IQ Trust Center for security and governance review.

Review implemented controls, data handling, published diligence documents, and roadmap boundaries before an Industrial IQ diagnostic.

Read-onlyDiagnostic workflow
No write-backSource systems remain buyer-controlled
Human reviewRequired before action
Executive AI governance layer showing risk controls, evidence records, approval checkpoints, and audit-ready decision support.
Trust controls make source traceability, confidence tiering, human review, and auditability visible before remediation decisions.
Trust boundary

Current controls, published material, roadmap, and limits

TopicIndustrial IQ Trust BoundaryDecisionSecurity, data handling, procurement, and governance reviewCoverageGlobal industrial markets

AI2COE Trust Center: The Trust Center explains the control posture behind Industrial IQ so enterprise buyers can inspect data handling, review boundaries, and evidence discipline before adoption. Review AI2COE's diagnostic safety model for source handling, no ERP write-back, human review, confidence tiers, report ownership, and audit controls.

Review Trust Controls
Control reviewerCISO, CIO, legal, procurement, governance, data owners, and executive sponsors evaluating diagnostic boundaries
Control materialUpload lifecycle, authentication, retained metadata, report ownership, audit events, policy documents, and data-handling commitments.
Published boundaryA trust view of no ERP write-back, human review, confidence tiers, source-data handling, report ownership, and governance limits.
Trust next stepReview the controls, then use Snapshot or sample reports to inspect the evidence model before private upload.
Current readiness

Current operating status and buyer review boundary.

StageStatusInterpretation
Pilot / demoReadyLocal and controlled founder-led pilots; authenticated uploads; report generation; admin audit layer.
Paid founder-led pilotReady with controlsAppropriate for selected customers after NDA, data-handling commitment, and manual onboarding.
Public Snapshot evaluation pathControlled previewThe public Free Industrial IQ Snapshot is a bounded evaluation path for sample or limited uploads. Broader unattended self-serve expansion still requires OAuth expansion, backup evidence, retention automation, monitoring evidence, and enterprise hardening.
Large enterprise procurementNear-readyDPA template, Engagement SLA, Data Handling Commitment, Security Overview, SOC 2 self-attestation, and Procurement FAQ now published. Remaining: SOC 2 Type II audit, production cloud hardening, uptime monitoring.
Data lifecycle

From approved export to governed evidence and source-file purge.

Industrial IQ uses a bounded, read-only diagnostic path. Retained governance metadata is disclosed separately from uploaded source files.

Review Data Handling
01 Upload export Approved CSV or workbook enters the diagnostic session.
02 Run diagnostic Field mapping, source-fit checks, and selected engine analysis.
03 Generate evidence Findings, scores, confidence tiers, limitations, and owner actions.
04 Purge source file Source files are purged after report generation according to the disclosed handling boundary.
05 Retain governance metadata Open Findings, report ownership, summary metrics, usage, feedback, and audit events may remain.
Implemented controls

Controls a security, legal, or procurement reviewer can inspect now.

Identity & Access

Identity & Access

Email verification gate, complete business profile, locked identity fields, current-password update checks, owner-only admin authorization, and session-based access control.

Report Governance

Report Governance

Report ownership records, expiring report links, persistent in-browser Open Findings, immediate-session artifact downloads, and generated-by attribution on report artifacts.

Diagnostic Safety

Diagnostic Safety

No ERP write-back. Confidence tiers separate evidence-ready findings from review candidates. Engine-specific controls reduce unsafe catalog, inventory, procurement, finance, asset, reliability, readiness, and governance recommendations.

Admin Auditability

Admin Auditability

Admin dashboard views, exports, edit-page access, and updates are logged. User and lead edits write before/after JSON to the admin change ledger.

Browser Security

Browser Security

CSRF protection, HTTP-only sessions, SameSite cookies, X-Frame-Options, nosniff, referrer policy, and production-ready HSTS activation.

Data Handling

Data Handling

CSV diagnostic input is processed through isolated run folders and the uploaded source file is purged after report generation. Excel, Word, PDF, and CSV downloads are available only in the active generation session. AI2COE retains Open Findings, summary metrics, report ownership, quota usage, feedback, and audit metadata only.

Data Residency

Data Residency

AI2COE diagnostic processing is currently hosted in the United States (primary). European Union accounts requiring in-region data processing and a GDPR Article 28 DPA should contact support@ai2coe.com with 'DPA Request' in the subject. Gulf Cooperation Council (GCC) accounts may request a data-handling commitment specific to their jurisdiction. In-region EU and GCC hosting is on the enterprise roadmap. Custom data residency arrangements are available by agreement for enterprise pilot accounts.

Published diligence documents

Open the evidence needed for enterprise review.

Agentic AI control status

Current controls and unsupported capabilities are separated explicitly.

Tool-using AI requires identity, authority, data scope, source traceability, prompt-injection resistance, human review, evaluation, monitoring, incident handling, and decommissioning controls.

Review the risk model
ImplementedNo operational write-back and human review before action
Controlled demoFixed read-only skill allowlist, R0-R2 authority, source references, injection quarantine, and formula neutralization
Documented processIdentity, tenant, policy, incident, version, evaluation, and decommissioning requirements
PlannedShort-lived external credentials and narrowly authorized read-only connectors
Not currently supportedOperational execution, transaction submission, autonomous remediation, live OT control, or external-agent collaboration
Current controls versus roadmap

Implemented, published, and future controls remain separate.

Control areaCurrent statusEvidence availableNext maturity step
No ERP write-backLiveTrust Center, upload workflow language, no-write-back pageContinue buyer-specific architecture review during enterprise pilots.
Read-only diagnostic workflowLiveExport-first upload path and engine pagesExpand lightweight health and route monitoring around diagnostic workflows.
Source-file purge after report generationLive for disclosed diagnostic flowsData Handling Commitment and Data Retention pagesContinue retention automation and buyer-specific DPA review where required.
Open Findings retentionLiveAuthenticated Open Findings and report ownership recordsClarify retention limits in customer-specific engagement terms.
Summary metrics and audit metadataLiveAdmin auditability, usage, report ownership, and governance metadataExpand procurement-ready audit export coverage as enterprise pilots mature.
Human review and confidence tiersLiveEngine pages, sample reports, and methodology pagesIncrease owner-review workflow depth for multi-site programs.
DPA and SLAPublishedDPA template and Engagement SLA pagesCountersigned versions available during scoped buyer review.
Security overview and architecturePublishedSecurity Overview, Architecture, BC/DR, Procurement FAQMaintain security questionnaire response pack for enterprise reviews.
SOC 2 self-attestationPublished bridge documentManagement self-attestation pageDoes not replace independent SOC 2 Type I or Type II audit.
SOC 2 Type IIRoadmap / not certifiedExplicit Trust Center boundaryFormal audit remains roadmap; do not claim certification until complete.
Data residencyCurrent primary hosting disclosedTrust Center and Data Handling pagesEU/GCC in-region hosting remains enterprise roadmap or custom agreement topic.
Role-based access controlsFounder/admin and authenticated user controls liveOwner-only admin authorization and report ownership modelExpanded RBAC remains a future enterprise hardening step.
Trust FAQ

Resolve the first security and governance questions.

Does AI2COE write back to SAP, Maximo, Oracle, or any ERP?

No. Industrial IQ is diagnostic-first. It analyzes uploaded operational exports and produces evidence for review. No automatic ERP record changes, deletions, merges, policy updates, or write-back actions are performed by any engine.

How is report access controlled?

Reports are tied to the logged-in user who generated them. Report links expire by default, downloads require authentication, and owner-admin access is restricted to the founder account.

What protects account and profile integrity?

New accounts require profile completion, explicit consent, and email verification before protected workflows are available. Important identity fields are locked, while editable profile updates require authentication.

What can be audited?

Admin views, exports, report access, downloads, profile changes, and admin edits are written to audit logs. Admin edits also preserve before/after values in a separate change ledger.

Has AI2COE completed SOC 2 Type II certification?

No. AI2COE is pilot-ready and has not completed SOC 2 Type II certification yet. The Trust Center separates controls already implemented from controls required before broad enterprise production hosting.

Security review

Validate the boundary before private upload.

Review the Security Brief, data-handling commitment, DPA, architecture, and engagement terms against your own controls before authorizing a diagnostic.

AI2COE Copilot