Authorization in context
Use tenant, role, entitlement, and support-access boundaries so people have the scope required for their operational responsibility.
Trust and evidence
ciliot is designed around precise, reviewable controls: tenant-aware authorization, source-aware evidence, contextual workflows, and clear limits. We do not present those controls as an absolute guarantee or a shortcut to a customer’s compliance responsibilities.
A disciplined foundation
Security, resilience, data governance, and operating evidence need to be designed into the product and reviewed in the customer’s actual environment. The public summary below explains the intended approach—not a certification or universal claim.
Use tenant, role, entitlement, and support-access boundaries so people have the scope required for their operational responsibility.
Retain source, event-time, configuration, calibration, response, and report context so the scope of a record can be reviewed.
Design for the reality of device, power, gateway, and connectivity disruption; surface gaps rather than hiding them.
Data as operational evidence
In cold-chain operations, an in-range reading is not by itself a compliance conclusion. A useful record makes its source, calibration, applicable regime, timing, completeness, and response history clear to the reviewer.
What a review needs
Privacy and service boundaries
Refrigeration telemetry may become personal data when it is associated with users, support actions, vehicle routes, or future people-sensing services. Customer deployment needs to define data classes, owners, retention, locations, and access boundaries.
Collect, display, and retain the data needed for the agreed service purpose; do not use a marketing surface to expose customer or operational data.
Identify the tenant administrator, security/IT owner, service owner, support path, and escalation contacts before operating a production service.
Assess new data types, integrations, camera/audio/biometric features, locations, and retention changes through the appropriate governance process.
Claims governance
Product, performance, security, customer, and commercial claims require current evidence and named approval before publication.
Only what a released feature and current service documentation support, with confirmation from the accountable product owner.
A defined methodology, environment, period, and independently reviewable result. We do not generalise a result beyond its stated scope.
A customer-specific baseline, formula version, period, approval, and written permission. A generic savings percentage is not an approved ciliot claim.
Formal scope and evidence, an expiration or renewal date, and legal/security approval. Product controls do not themselves confer regulatory compliance.
Bring your requirements
A pilot conversation can make the customer-specific boundaries, responsibilities, and review criteria explicit before a production commitment.