Operator
Run, stop and acknowledge. Cannot change parameters, envelopes or acceptance decisions.
Weldeon writes to industrial equipment in a safety-critical process. That imposes obligations beyond ordinary software security — and it starts with the platform working perfectly well with no connection to us at all.
Perception, reasoning and control all run on a factory edge appliance on your shop-floor network. There is no inbound path from the internet, and the control loop does not depend on an outbound one.
Cloud sync exists — fleet learning, benchmarks, long-horizon genealogy — and it is genuinely useful. But it is opt-in per site and per data class, and turning it off degrades nothing about the welds you make today.
We think this is the only defensible posture for a system that can move a robot.
Security in a physical process is mostly about authority, not encryption.
Part geometry, procedures and NDT history are among the most sensitive assets a fabricator owns.
Access control that mirrors the authorities your quality system already defines.
Run, stop and acknowledge. Cannot change parameters, envelopes or acceptance decisions.
Owns procedures and envelopes. Can change what the platform is permitted to do, within code.
Accepts or rejects indications. The only role that can close an NDT decision.
Manages users, sites, integrations and sync policy. Cannot approve welds.
Read-only across genealogy, deviations and configuration history.
No standing access. Time-boxed, customer-approved, fully logged sessions only.
We would rather tell you what is in place today than imply certifications we have not yet earned.
Edge-first design, bounded authority and tenant isolation are implemented today, and documented in the security note we share under NDA.
Code review, dependency scanning, signed releases and pinned runtimes across the edge fleet.
A published disclosure address, triage commitments and customer notification thresholds.
SOC 2 Type II and ISO 27001 are on the roadmap and are [ASPIRATIONAL] until independently audited. We will not claim them before then.
We complete security questionnaires, support architecture reviews, and welcome customer-led penetration testing of the edge appliance.
In a code-bound process, the strongest security property is that nothing happened without a record of who or what decided it.
0
bytes that must leave your site for the control loop to close
0
standing Weldeon access to customer environments
100%
of parameter writes bounded by the qualified WPS envelope
TLS 1.3
in transit; encryption at rest on edge and in tenancy
Certification status: SOC 2 Type II and ISO 27001 are [ASPIRATIONAL]. Current controls are described in the security note available under NDA.
“A system that can move a robot should assume it will one day be asked to explain itself.”
Not yet. SOC 2 Type II and ISO 27001 are on our roadmap and we will say so clearly the day they are independently audited. Today we share our architecture note, control descriptions and questionnaire responses under NDA.
There is no standing access. Support sessions are time-boxed, initiated by you, scoped to a specific issue and fully logged.
Nothing changes on the shop floor. The loop is local. Genealogy and telemetry buffer on the appliance and reconcile when connectivity returns.
Not for other customers, and not without a written agreement. Models improve on your data for your sites by default; fleet learning is a separate, opt-in decision.
Book a pilot on one cell or line. We agree the scorecard before we start — first-pass yield, rework hours, defect escapes, takt — and we report against it in the open.