Security
Your memory. Your infrastructure. Your control.
Nemeton Works handles the data that describes how your plant runs — machine events, maintenance history, the structured knowledge of your operation. That demands sovereign intelligence infrastructure, governed and auditable, not a black box you have to take on trust. This is how we hold it, where it lives, and who is allowed to change it.
The machine proposes. The human authorises. The system remembers. The institution improves.
Data sovereignty
The memory is yours, and its location is declared.
Operational memory is too valuable to hide behind vague infrastructure claims. Deployment location, enabled processors and transfer safeguards belong in the customer agreement and assurance record.
Declared data location
Production data location is recorded per deployment and disclosed in the customer agreement and processor register. We do not make a residency promise until the configured region and each enabled integration have been verified.
You own your operational memory
The asset register, the fault history, the structured knowledge Nemeton Works builds — it is yours. It is exportable, it leaves with you if you leave, and it is never sold, syndicated, or pooled with other operators. We hold it on your behalf; we do not own it.
No training on your data without consent
We do not feed your operational data into model training. Inference calls that draft a brief or a finding are scoped, pseudonymised where possible, and governed by data processing agreements — and your records are never used to improve a shared model without your explicit, written consent.
Tenant isolation by default
Organisation boundaries are enforced in server authorisation and database Row Level Security. We test these controls because no security boundary should rely on a claim that software can never fail.
Governance & human-in-the-loop
The machine drafts. A person authorises. The record remembers both.
Governed intelligence means a human is structurally in command of every change to a system of record. Nothing is written autonomously, and nothing happens that you cannot later account for.
No autonomous writes
Nemeton Works does not write to SAP, your CMMS, or any system of record on its own. The machine proposes a draft; nothing reaches a system of record until a competent human has authorised it. There is no silent action.
Every write is reviewed and attributable
AI outputs land in an approval queue, in review by default. A named person reviews each one, and every memory write carries who approved it and when. Accountability is recorded, not assumed.
Human-in-the-loop, by design
Authorisation is a structural step in the workflow, not an optional setting an administrator can switch off. Agent runs are scheduled and logged, and their outputs wait for review — the human is in the loop because the system has no path around them.
Auditable workflow events
Material workflow events, proposals and approval decisions are designed to produce tenant-scoped audit records. Audit coverage is verified route by route and expanded as new consequential actions are introduced.
Practices
Practical controls, stated honestly.
What follows is what we actually do — not a wishlist and not a badge wall. Where we align to a standard, we say aligned. We do not claim certifications we cannot evidence.
Encryption in transit and at rest
HTTPS is enforced for hosted services. Managed providers encrypt stored data using their documented controls. Integration secrets and API keys are kept outside source control and restricted to the server-side services that need them.
Least-privilege access
Access follows role inside each organisation, and service credentials are scoped to the minimum permissions a task requires. Sessions use signed cookies with configurable expiry. People and systems get what they need to do the job, and no more.
Row-level security on tenant data
Tenant isolation is enforced by row-level security at the database layer, so the boundary holds even if application code has a flaw. Database access uses parameterised queries through a typed client, and input is validated at every API boundary.
Hardened delivery and headers
Security headers are applied across the public platform, changes are reviewed through pull requests, and dependencies are checked as part of release assurance. Secrets must remain outside version control. We align practices to UK GDPR and recognised guidance rather than claim certifications we have not earned.
In the event of a security incident affecting personal data, we notify affected customers and the Information Commissioner’s Office (ICO registration ZC161313) within 72 hours where required under UK GDPR. Our incident response procedure and security documentation are available to customers on request.
Review our security posture.
If you run a security, risk, or procurement review, talk to us directly. We will walk you through data residency, the human-in-the-loop controls, and our practices — and share the documentation your process needs.