Trust and deployment boundaries

Clarity before access.

This page describes the current advisory scope. It does not substitute for customer security review, contracting, or a technical data-handling schedule.

Current standard-platform scope

Advisory output

The platform prepares research, drafts, checklists, analyses, and decision structure for qualified human review.

Named-user access

Pilot and annual access are assigned to identified users. Shared accounts are not part of the commercial model.

No plant-system integration

The standard platform does not connect to SCADA, historians, SAP, Azure, Entra, cameras, or plant equipment.

No autonomous action

The platform does not execute plant, safety, regulatory, engineering, environmental, or financial decisions.

Input and photo policy

Permitted starting inputs

Public, synthetic, redacted, or otherwise customer-approved information.

Plant-specific information

Documents, text, history, operating data, and photos require written customer authorization before use.

Manual photos

User-selected uploads are available in applicable copilots, subject to the same customer data rules.

Prohibited by default

Credentials, unrestricted confidential information, personal data, export-controlled information, and unapproved plant-sensitive material.

Important transmission boundary

The current platform is hosted. Information entered or uploaded is transmitted to hosted services for processing. Do not submit plant-sensitive material unless the customer has approved the use and accepted the applicable data-handling terms.

Enterprise diligence

Facts supplied before authorized use.

CementOps will not replace unknown technical facts with marketing claims. The applicable security and data-handling package must identify:

  • Hosting and processing providers and regions
  • Applicable model providers and configurations
  • Prompt, output, account, photo, backup, and deletion treatment
  • Provider-training settings and contractual restrictions
  • Administrative access, authentication, logging, and account revocation
  • Subprocessors and incident-notification procedures

Configured or integrated systems are separate.

Any customer-specific knowledge loading, identity integration, system connection, automated ingestion, or custom workflow requires separate discovery, architecture, security approval, schedule, acceptance criteria, and commercial terms.