Protecting your factory data with zero-compromise security
Manufacturing workflows demand extreme confidentiality and integrity. FactoryNerve combines kernel-level PostgreSQL Row-Level Security, AES-256 encryption, and AWS Mumbai data residency to keep your operations ironclad.
PostgreSQL Row-Level Security (RLS)
Every SQL query is bound to the authenticated tenant at the database kernel level via PostgreSQL RLS policies. It is physically impossible for one factory's queries to leak or read another organization's records.
- Kernel-level session tenant binding (`SET LOCAL app.current_tenant_id`)
- Strict defense-in-depth: ORM filters backed by database policies
- Isolated search scopes across all models, batches, and dispatches
End-to-End Encryption
All sensitive production data, employee records, and OCR image documents are protected both in transit across public networks and at rest in persistent storage volumes.
- AES-256 volume & database encryption at rest
- Strict TLS 1.3 enforced for all client and internal HTTP connections
- KMS-managed key rotation with no hardcoded credentials
Indian Data Residency (AWS Mumbai)
FactoryNerve processes and archives 100% of core manufacturing logs, inventory ledgers, and employee attendance within Indian borders, compliant with national IT and industrial data regulations.
- Primary database hosted in AWS Asia Pacific (Mumbai) ap-south-1
- Zero cross-border transfer of customer production data
- Edge caching via secure regional network nodes
Immutable Audit Trails
Every weighbridge slip, stock adjustment, shift approval, and OCR override generates a permanent audit trail stamped with timestamp, user ID, client IP, and previous state.
- Append-only audit logs with cryptographically verifiable history
- Role-enforced change tracking on dispatch, scrap, and finance records
- Automated drift alerts on reconciliation discrepancies
Role-Based Access Control (RBAC)
Granular permission matrix prevents unauthorized viewing of financial margins, dispatch logs, or raw attendance metrics by floor-level or cross-departmental staff.
- Discrete persona lanes: Owner, Plant Manager, Shift Supervisor, Floor Operator
- Secure Google OAuth and password hashing with salted bcrypt/argon2
- Instant multi-session revocation upon role downgrade or offboarding
Compliance & Industry Standards
Built from the ground up to satisfy rigorous industrial auditing standards, tax compliance requirements, and data subject privacy laws.
- SOC 2 Type I audit alignment in progress (target Q3 2026)
- GDPR and Digital Personal Data Protection (DPDP) ready architecture
- Standard Data Processing Addendum (DPA) available on demand
12-Point Security & Governance Matrix
Continuous security validation enforced across our entire stack, from API gateways to bare database storage.
Vulnerability Disclosure
Responsible bug bounty & reporting
We welcome reports from independent security researchers. If you have discovered a potential security vulnerability, please notify us immediately. We respond to verified security disclosures within 24 hours.
Incident Response SLA
Rapid escalation & mitigation
Our NIST-aligned Incident Response Plan ensures that severity-1 incidents are triaged within 15 minutes. In the event of a confirmed breach, affected customers receive direct notifications within 24 hours.