Proof controls buyers expect before they upload operational data.
Uploaded data moves through a controlled diagnostic lifecycle.
This visual summarizes the buyer-safe operating model. The detailed control catalogue and policy links remain below for security, legal, and procurement review.
Security and procurement reviewers should see the trust boundary at a glance.
Icons are paired with visible labels and status tags. They summarize the control posture without replacing the detailed policy text below.
No ERP write-back
Diagnostics do not autonomously change SAP, Maximo, Oracle, EAM, CMMS, procurement, or inventory systems.
Read-only workflow
Industrial IQ evaluates exported operational data and produces review evidence before any buyer-controlled remediation.
Source-file purge
Uploaded source files are used to generate report packs and are purged after report generation according to disclosed handling boundaries.
Human review
Confidence tiers and review queues separate evidence-ready findings from owner-review candidates.
Confidence tiers
Findings carry confidence context so buyers can distinguish strong evidence from review-required signals.
Audit metadata
Open Findings, report ownership, continuity metadata, and audit events support governance where required.
DPA / SLA path
DPA, engagement SLA, security overview, and procurement review language are available for buyer review.
SOC 2 boundary
AI2COE does not claim SOC 2 Type II certification; audit maturity remains a roadmap item until completed.
AI2COE is designed to produce evidence without creating operational risk.
Industrial AI adoption fails when a platform asks for trust before producing evidence. AI2COE reverses the order: upload an operational export, generate a controlled diagnostic, review confidence-tiered findings, and decide whether remediation is worth funding.
The portal deliberately avoids automatic ERP write-back. This matters across every engine: catalog review, inventory policy, procurement leakage, working-capital interpretation, asset-to-part linkage, maintenance readiness, AI readiness, and evidence governance all require source-backed review before action.
Evidence without uncontrolled source-data retention.
Diagnostic evidence is not uncontrolled remediation.
This boundary is intentionally visible for CIO, CISO, procurement, and operations reviewers.
What the CTO, CIO, CISO, CRO, and procurement team should see.
Identity & Access
Email verification gate, complete business profile, locked identity fields, current-password update checks, owner-only admin authorization, and session-based access control.
Report Governance
Report ownership records, expiring report links, persistent in-browser Open Findings, immediate-session artifact downloads, and generated-by attribution on report artifacts.
Diagnostic Safety
No ERP write-back. Confidence tiers separate evidence-ready findings from review candidates. Engine-specific controls reduce unsafe catalog, inventory, procurement, finance, asset, reliability, readiness, and governance recommendations.
Admin Auditability
Admin dashboard views, exports, edit-page access, and updates are logged. User and lead edits write before/after JSON to the admin change ledger.
Browser Security
CSRF protection, HTTP-only sessions, SameSite cookies, X-Frame-Options, nosniff, referrer policy, and production-ready HSTS activation.
Data Handling
CSV diagnostic input is processed through isolated run folders and the uploaded source file is purged after report generation. Excel, Word, PDF, and CSV downloads are available only in the active generation session. AI2COE retains Open Findings, summary metrics, report ownership, quota usage, feedback, and audit metadata only.
Data Residency
AI2COE diagnostic processing is currently hosted in the United States (primary). European Union accounts requiring in-region data processing and a GDPR Article 28 DPA should contact support@ai2coe.com with 'DPA Request' in the subject. Gulf Cooperation Council (GCC) accounts may request a data-handling commitment specific to their jurisdiction. In-region EU and GCC hosting is on the enterprise roadmap. Custom data residency arrangements are available by agreement for enterprise pilot accounts.
What is available now, what is published for review, and what remains roadmap.
AI2COE is designed for low-risk diagnostic evaluation: exported data, no production-system write-back, source-file purge after report generation, evidence traceability, confidence tiers, and human review. The table below separates implemented controls from future maturity items so security and procurement teams can review the boundary without overclaiming.
| Control area | Current status | Evidence available | Roadmap / next maturity step |
|---|---|---|---|
| No ERP write-back | Live | Trust Center, upload workflow language, no-write-back page | Continue buyer-specific architecture review during enterprise pilots. |
| Read-only diagnostic workflow | Live | Export-first upload path and engine pages | Expand lightweight health and route monitoring around diagnostic workflows. |
| Source-file purge after report generation | Live for disclosed diagnostic flows | Data Handling Commitment and Data Retention pages | Continue retention automation and buyer-specific DPA review where required. |
| Open Findings retention | Live | Authenticated Open Findings and report ownership records | Clarify retention limits in customer-specific engagement terms. |
| Summary metrics and audit metadata | Live | Admin auditability, usage, report ownership, and governance metadata | Expand procurement-ready audit export coverage as enterprise pilots mature. |
| Human review and confidence tiers | Live | Engine pages, sample reports, and methodology pages | Increase owner-review workflow depth for multi-site programs. |
| DPA and SLA | Published | DPA template and Engagement SLA pages | Countersigned versions available during scoped buyer review. |
| Security overview and architecture | Published | Security Overview, Architecture, BC/DR, Procurement FAQ | Maintain security questionnaire response pack for enterprise reviews. |
| SOC 2 self-attestation | Published bridge document | Management self-attestation page | Does not replace independent SOC 2 Type I or Type II audit. |
| SOC 2 Type II | Roadmap / not certified | Explicit Trust Center boundary | Formal audit remains roadmap; do not claim certification until complete. |
| Data residency | Current primary hosting disclosed | Trust Center and Data Handling pages | EU/GCC in-region hosting remains enterprise roadmap or custom agreement topic. |
| Role-based access controls | Founder/admin and authenticated user controls live | Owner-only admin authorization and report ownership model | Expanded RBAC remains a future enterprise hardening step. |
Eight diagnostic engines create the Industrial IQ platform.
PartsCleanse AI
MRO catalog deduplication, field quality, UOM consistency, and duplicate capital exposure.
View engineInventoryMind AI
Dead stock, slow-moving stock, excess, stockout risk, and duplicated stock exposure.
View engineProcureMind AI
Emergency procurement, stocked-but-purchased events, repeated buys, supplier alias risk, and price variance.
View engineFinanceMind AI
Duplicate capital exposure, carrying cost, emergency premium, and recoverable value scenarios.
View engineAssetMind AI
Asset-to-part linkage, critical spare coverage, obsolete asset spares, and plant risk heatmaps.
View engineReliabilityMind AI
Work-order spare availability, false stockout risk, repeat demand, and shutdown readiness.
View engineReadyMind AI
ERP data quality, governance readiness, operational readiness, and first-use-case recommendation.
View engineGovernanceMind AI
Evidence traceability, review-level assignment, owner approval, auditability, and no-write-back governance.
View engineHonest launch-readiness classification.
| Launch stage | Status | Interpretation |
|---|---|---|
| Pilot / demo | Ready | Local and controlled founder-led pilots; authenticated uploads; report generation; admin audit layer. |
| Paid founder-led pilot | Ready with controls | Appropriate for selected customers after NDA, data-handling commitment, and manual onboarding. |
| Public self-serve launch | Near-ready | Needs production domain config, SMTP, OAuth credentials, HTTPS, backups, retention automation, and monitoring. |
| Large enterprise procurement | Near-ready | DPA template, Engagement SLA, Data Handling Commitment, Security Overview, SOC 2 self-attestation, and Procurement FAQ now published. Remaining: SOC 2 Type II audit, production cloud hardening, uptime monitoring. |
All compliance documents in one place.
| Document | Purpose | Audience | Status |
|---|---|---|---|
| Data Handling Commitment | What happens to uploaded catalog CSV files — purge commitment | Legal, CISO, Procurement | Published |
| Data Processing Agreement (DPA) | GDPR Article 28 DPA template for countersignature | Legal, EU/UK/GCC accounts | Published |
| Engagement SLA | 15-business-day delivery commitment and overrun remedy | Procurement, Finance | Published |
| Security Overview | Encryption, access controls, data residency, incident response | CISO, Security team | Published |
| SOC 2 Self-Attestation | CEO attestation of SOC 2 Trust Service Criteria controls | Enterprise procurement | Published |
| Architecture Overview | Data flow diagram, isolation boundaries, purge pathway | CTO, Security architect | Published |
| Procurement FAQ | W-9, insurance, payment terms, contract vehicle answers | Procurement, Sourcing | Published |
| Refund & Cancellation Policy | Milestone-based refund schedule and SLA overrun remedy | Finance, Procurement | Published |
| Getting Started Guide | CSV format specs, engagement process, report deliverables | IT, Operations lead | Published |
| Acceptable Use Policy | Permitted and prohibited uses of the portal | Legal, IT | Published |
| BC/DR Summary | Recovery objectives, backup strategy, incident communication | CISO, Enterprise procurement | Published |
| Release Notes | Product changelog and version history | Technical evaluators | Published |
| SOC 2 Type II Report | Independent auditor's examination of security controls | Enterprise procurement | Planned — 12-18 months |
Questions a buyer, CIO, or CISO will ask first.
Does AI2COE write back to SAP, Maximo, Oracle, or any ERP?
No. Industrial IQ is diagnostic-first. It analyzes uploaded operational exports and produces evidence for review. No automatic ERP record changes, deletions, merges, policy updates, or write-back actions are performed by any engine.
How is report access controlled?
Reports are tied to the logged-in user who generated them. Report links expire by default, downloads require authentication, and owner-admin access is restricted to the founder account.
What protects account and profile integrity?
New accounts require profile completion, explicit consent, and email verification before protected workflows are available. Important identity fields are locked, while editable profile updates require authentication.
What can be audited?
Admin views, exports, report access, downloads, profile changes, and admin edits are written to audit logs. Admin edits also preserve before/after values in a separate change ledger.
Has AI2COE completed SOC 2 Type II certification?
No. AI2COE is pilot-ready and has not completed SOC 2 Type II certification yet. The Trust Center separates controls already implemented from controls required before broad enterprise production hosting.
What decision this page helps the buyer make.
Can Industrial IQ produce diagnostic evidence without uncontrolled system change or unclear data handling?
CIO, CISO, legal, procurement, and governance reviewers checking boundaries before upload.
Choose the next action by buyer readiness.
Choose the next action based on where the buying committee is now: proof review, data readiness, pilot scoping, or security validation.
Inspect evidence rows, confidence tiers, limitations, scores, and owner actions before sharing private data.
View Sample Reports Stage: Have an export ready Run an Industrial IQ SnapshotStart with exported operational data or sample data and route the issue to the right diagnostic engine.
Run Snapshot Stage: Need committee alignment Download the buyer evaluation guideUse the finance, operations, technology, procurement, maintenance, and security checklist for internal review.
Download Buyer Guide Stage: Active initiative Request a founder-led pilotUse this path when ERP migration, inventory action, procurement leakage, or AI readiness needs a scoped diagnostic.
Request Pilot Stage: Security review Review the security briefValidate no ERP write-back, source-file purge, human review, access controls, DPA/SLA path, and retention boundaries.
Review Security BriefTrust boundary: No ERP write-back. Source files purged after report generation. Human review before action. Sample reports use demonstration data until replaced by uploaded-data diagnostics.
Trust should show the control boundary visually.
The review path makes source exports, confidence tiers, human review, and no ERP write-back clear before data is uploaded.
MRO stores, assets, maintenance, procurement, and site context are shown as the operating layer behind every diagnostic.
Industrial IQ starts with CSV or workbook exports, field mapping, and source-fit review before findings are treated as evidence.
Findings show source evidence, confidence, reason codes, assumptions, limitations, and human-review status.
Actions are accepted, rejected, deferred, or escalated by accountable owners. No ERP write-back happens automatically.
Use this page to validate the operating boundary before data is uploaded.
Trust review gives security, procurement, legal, IT, and governance reviewers clear language before a diagnostic starts.
CISO, CIO, procurement, legal, risk, security, data governance, and enterprise architecture teams.
Hosting, access, data handling, retention, source-file purge, no ERP write-back, human review, DPA, SLA, and buyer-security review language.
A buyer-security review path that clarifies what Industrial IQ does, what it does not do, and what can be reviewed during procurement.
Read-only diagnostics, no ERP write-back, source-file purge after report generation, and human review before action.