Skip to content
Trust Quality AssuranceManufacturing Intelligence

Documentation · platform release 2026.3

Documentation contents

Security & compliance

Process parameters, recipes and quality records are among your most sensitive assets. This page is written for the people who have to sign off on us holding them.

Updated July 2026 · 13 min read

Control summary

Security controls
DomainControlDetail
ProgrammeSOC 2 Type II alignedAccess, change management, monitoring, vendor risk and incident response
EncryptionTLS 1.3 in transit, AES-256 at restCustomer-managed keys available on enterprise agreements
IdentitySAML 2.0 / OIDC SSO with SCIMMFA enforced by your identity provider; no local passwords by default
AccessRole-based, scoped by site, line, product family, supplierLeast privilege with segregation of duties on record closure
AuditImmutable, append-only audit trailReads, writes, approvals, signatures and model decisions
Data protectionRegional residency, per-tenant isolationNo cross-tenant model training or data reuse
TestingAnnual third-party penetration testExecutive summary shared under NDA
Availability99.95% monthly SLARPO 15 minutes, RTO 4 hours

Access model

Capability and scope are separate. A role says what someone may do; the scope says which records it applies to. This is what makes a shared dashboard safe across plants that must not see each other's data.

  • Scope dimensions: site, area, line, product family and supplier. Scopes intersect rather than accumulate.
  • Segregation of duties: the platform can prevent the author of a corrective action from approving its closure.
  • Service accounts are separate principals with their own narrow scopes and rotating secrets.
  • Read-only auditor role for internal audit, notified bodies and customer quality representatives.
  • Break-glass administrative access is disabled by default, time-boxed and fully audited when enabled.

Data integrity and electronic records

  • Released quality records are append-only. A correction creates a new version; the prior state is retained and visible.
  • Electronic signatures bind the signer identity, the meaning of the signature, the record version and the timestamp.
  • Audit entries cannot be edited or deleted by any role, including tenant administrators.
  • Retention policies are configured per record class and enforced automatically, including legal hold.
  • ALCOA+ principles — attributable, legible, contemporaneous, original, accurate, plus complete, consistent, enduring and available — are the design basis for the record model.

Standards mapping

The platform supplies evidence. Certification remains a property of your configured, audited process — no software can grant it, and any vendor claiming otherwise should be treated with suspicion.

Standards coverage
StandardScopeWhat the platform contributes
ISO 9001Quality management systemProcess control records, management review KPIs, documented improvement loop
IATF 16949Automotive QMSCharacteristic-level SPC, PPAP evidence, layered process audit support, escalation records
AS9100DAerospace QMSTraveller, first article and nonconformance traceability with configuration history
ISO 13485Medical device QMSDesign history linkage, controlled documents, verified corrective action effectiveness
FDA 21 CFR Part 11Electronic records and signaturesSignature binding, audit trail, retention policy, validation package
VDA 6.3Process auditProcess-step evidence, capability data and corrective action closure per question block
ISO/IEC 27001Information securityControl mapping, risk register and supplier security review artefacts on request

AI governance

Principles

  • Models are decision support. A qualified person makes and owns the inspection decision.
  • Every inference retains its inputs, model version, confidence score and the human verdict.
  • Models are versioned with drift monitoring, champion/challenger evaluation and approval gates before promotion.
  • Any model can be withdrawn without losing the historical record of decisions it contributed to.
  • Training data stays within the tenant; your process data never trains a model served to another customer.

Security review pack

Supplied under NDA, usually within two business days of request. If your process needs something not listed, ask — the list grows from customer reviews.

  • SOC 2 Type II report and control mapping
  • Penetration test executive summary and remediation status
  • Network and identity architecture diagrams
  • Sub-processor list and data processing agreement
  • Business continuity and incident response summary
  • Completed CAIQ or your own security questionnaire
  • Validation package index for regulated programmes

Requests go to security@trustqualityassurance.com. Suspected vulnerabilities go to the same address with "vulnerability report" in the subject; we acknowledge within one business day.

Need something this page does not cover?

Solution architects answer technical questions directly — no ticket triage for pre-sales evaluation.

Ask an engineer