Identity and access
SSO via SAML and OIDC, role-based access control, and least-privilege scoping down to the individual line and workflow.
SOC 2 Type I in progress · Type II on the roadmap Aspirational
Duromex asks for permission to change what happens to your product. That is a serious ask, and it is why isolation, auditability, IP protection and fail-safe behaviour were in the first release rather than a later one.
Nothing exotic — just the controls an industrial buyer should refuse to proceed without.
SSO via SAML and OIDC, role-based access control, and least-privilege scoping down to the individual line and workflow.
Encryption in transit and at rest across the edge runtime, the control plane and every data store.
Per-tenant data and model scoping with permission-aware retrieval; no shared vector store, no shared memory.
Every agent action, its evidence, its citations and its write, recorded in an assurance-grade quality and safety trail.
Cloud, factory edge or fully on premises — with regional residency controls for multi-region groups.
Full tracing, twin and evaluation gating in CI, and runtime guardrails on every agent action.
Recipes, BOMs, product specs and quality data live inside your tenant boundary and are retrieved with permission-aware filtering.
Cross-factory learning improves shared defect, leak, foam-void and performance models without moving your recipes or quality data.
You can see what was retrieved, what was cited and what was written — for every action, retrospectively.
Your data, and in enterprise agreements the model artefacts trained on it, remain yours and are exportable.
Duromex can write to a press, a foaming machine, an assembly station, a tester and a robot cell. Every one of those write paths is idempotent, scoped, reversible and subordinate to the plant's existing safety systems.
Agents request; the safety layer decides. Graceful degradation and fail-safe stop for press, foamer, robot and product handling are part of the non-functional requirements, not an add-on.
Appliance manufacturing is regulated on safety, energy and refrigerants. Duromex captures the evidence as a by-product of running the line.
| Area | What applies | How Duromex helps |
|---|---|---|
| Product safety | IEC 60335 appliance safety | Test acceptance evidence and traceability captured per unit |
| Energy | Energy-efficiency regulations and ratings | Thermal-performance forecasting and rating conformance tracking |
| Refrigerants | F-gas and refrigerant regulations | Leak detection, charge accuracy and loss tracking with evidence |
| Quality systems | Non-conformance, disposition and traceability | Immutable action log integrated with MES and quality systems |
| Information security | SOC 2 Aspirational | Type I in progress, Type II on the roadmap |
| Data protection | Regional residency requirements | Regional deployment and on-prem options |
This is how a validated process stays validated.
Golden datasets and judge models evaluate every model and prompt change in CI. A regression blocks the release.
Recipe, layout and changeover changes are simulated in the line-and-product twin and must hit the predicted quality, yield and takt targets.
Signed OTA updates roll out to a canary line first, with automatic rollback on regression.
Anything touching safety, warranty or a validated process requires explicit human approval, recorded in the audit trail.
The four groups who can stop a deployment, and what each one gets.
SSO, RBAC, encryption, tenancy isolation, documented data flows and an on-prem option.
Scoped write authority, fail-safe stop, offline-capable edge and no dependency on a WAN link for control.
IEC 60335 evidence, non-conformance integration, immutable traceability and twin-gated change control.
Audit logging, IP protection, least privilege, canary and rollback, and the SOC 2 roadmap.
Every stage the unit passes through leaves signed evidence: what was seen, what was decided, what was written and who approved it. The audit trail is a by-product of the loop, not a separate exercise.
Duromex is pre-launch. This is stated plainly rather than implied otherwise.
SOC 2 in progress Aspirational
customer data used for cross-tenant training
actions with retained evidence
target initial response on security enquiries
“Our end-of-line functional testers told us what failed. They never told us which press stroke or foam shot caused it. That link is the whole product.”
“Foam voids are invisible until the energy rating comes back wrong. Predicting density distribution before the cabinet cures is the part I could not buy anywhere else.”
“If it writes to the press, it needs an audit trail a quality auditor accepts. Duromex started there instead of bolting it on.”
Not in a way that moves your data. Cross-factory learning is federated and preserves tenant IP, product recipes and quality data boundaries. Participation is opt-in.
It is written at the edge and replicated to your tenant in the control plane, or kept entirely on premises in an on-prem deployment. It is exportable in full.
Report to security@duromex.com. We acknowledge within one business day and will agree a remediation timeline with you. Aspirational A formal programme launches with general availability.
Yes, in the on-prem configuration. Model updates are then delivered through a controlled, signed offline channel.
We would rather answer 200 questions now than lose your trust after we have write access to a press.
Duromex is pre-launch. Figures shown are design-partner targets and modelled economics, not audited results. Ask us for the methodology.