Security & safety

Software that moves a machine has to earn it

Yarneon touches physical process. That raises the bar past normal SaaS security into process safety, OT segmentation and reversibility.

  • Bounded autonomy
  • Immutable audit
  • Operator override always

Safety model

Autonomy is granted, never assumed

Graduated autonomy
Every workflow moves observe → assist → bounded auto-control. Autonomy ceilings are per-setpoint policy, not a global switch.
Human-in-the-loop gates
Approval gates fire on deviation thresholds, new substrates, or any action outside the authorised envelope. Approvals are attributed and time-stamped.
Reversibility
Every control action ships with a revert path and a last-known-good setpoint. Operators can take manual control at any moment, from the HMI or the panel.
Immutable audit log
Assurance-grade, append-only record of every observation, decision, tool call, approval and actuation, exportable for buyer and regulatory audit.
Tenant isolation
Recipes, construction libraries and roll data are isolated per tenant. No cross-tenant training. Permission-aware retrieval with enforced citations.
Sandboxed tools
Agents call machines through a typed, scoped tool layer with rate and range limits. There is no path from a model output to an unbounded PLC write.
Deployment choice
Cloud, private VPC or fully on-prem via NVIDIA AI Enterprise for groups protecting dye-recipe IP. Data residency selectable per site.
Access control
SSO (SAML/OIDC), SCIM provisioning, RBAC down to workflow and setpoint, and break-glass procedures with mandatory review.

Compliance posture

The certifications buyers and auditors ask for

Textile buyers audit chemistry, labour and traceability. Enterprise IT audits everything else. Both get evidence rather than assurances.

  • SOC 2 Type I
    In progress ASPIRATIONAL, Type II planned
  • ISO 27001
    In progress ASPIRATIONAL
  • GDPR
    Aligned
  • IEC 62443
    OT security alignment
  • ZDHC MRSL
    Reporting supported
  • OEKO-TEX / bluesign
    Evidence export

Items marked ASPIRATIONAL are in progress and are stated as such deliberately. We would rather be boring about this than surprising.

OT posture

How we sit on your network

The edge appliance is the boundary

Yarneon does not put your PLCs on the internet. The appliance sits in a segmented cell, speaks to controllers over OPC UA and vendor protocols, and exposes nothing inbound.

  • Outbound-only mutual TLS; no inbound ports on the mill network
  • Purdue-model aware placement with a documented data diode option
  • Signed firmware and model artefacts, verified on load
  • Local operation with full function when the link is down
  • Per-tenant key isolation; models never trained across customers

Failure mode

Loses the internet, keeps the mill

If the uplink drops, the edge appliance keeps running the loop with local models and buffers the record until it can sync.

Override

One button

At the machine panel.

Audit

Immutable

Append-only, exportable.

Tool-call stream

Every call the agent made, in order

Machines, spectrophotometers, the optimiser and the humans are all tools. Calls go out, results come back, and the whole exchange is real, copyable text, the same record your auditor sees.

tool-call stream · RUN-4471
04:02:11 result: mes.get_lot("DL-4471") → 14 rolls · 3,180 kg · poplin 40s SUCCEEDED
04:02:12 call: twin.simulate(recipe_candidates=3, machine="jet-07") RUNNING
04:02:58 result: twin.simulate → best ΔE 0.52 · cycle 118 min · water 46 L/kg SUCCEEDED
04:03:01 call: colour.predict_recipe(substrate="cotton", standard="19-4028 TCX") RUNNING
04:03:03 result: colour.predict_recipe → Navy RGB 2.14% · Blue BRF 0.61% · Black B 0.08% SUCCEEDED
04:03:04 call: policy.check(action="dose", deviation=7.2%) → requires human approval APPROVAL
04:18:22 result: human.approve(user="colourist-on-shift", decision="approve", note="ok, hold ramp") SUCCEEDED
04:18:24 call: plc.dose(machine="jet-07", schedule="ramp-B") RUNNING
05:41:07 result: spectro.read(bath) → exhaustion 96.4% · bath ΔE 0.41 SUCCEEDED
06:22:40 result: vision.scan(roll=09) → WEFT_STREAK 412–445 m · severity 3 FAILED
06:22:41 call: cuopt.replan(cut_plan, constraint="ship_thu_0600") RUNNING
06:22:43 result: cuopt.replan → 33 m to seconds · ship date held SUCCEEDED
06:25:02 result: quality.release(lot="DL-4471") → 13 Grade A · 1 Grade B · packet signed SUCCEEDED

Guardrail in action

policy.check → requires human approval

At 04:03:04 the proposed recipe deviated 7.2% from the standing card, above the 5% autonomy ceiling for dye dosing at this mill. The agent stopped and asked. Fifteen minutes later a colourist approved it, and that approval is attributed, timestamped and reversible.

APPROVAL GATEAPPROVED 04:18

Failure handled honestly

vision.scan → WEFT_STREAK, roll 09

A 33 m weft streak is a real defect, and the run shows it as failed rather than smoothing it over. The mechanical root cause, a stenter pin-chain slip, was correlated automatically and raised as a work order.

STEP FAILEDRUN RECOVERED

Reasoning trace

The reasoning, written down

Goal, observation, plan, action, decision, handoff, outcome. A colourist can read this and disagree with it, which is the point. Autonomy a mill cannot argue with is autonomy a mill will not adopt.

  1. Goal01 / 10

    Land DL-4471 on Indigo 19-4028 TCX within ΔE 0.80, first time, before the Thursday 06:00 ship cut-off.

  2. Observation02 / 10

    Greige absorbency for this lot reads 8% above the card baseline, and incoming water hardness is 142 ppm, both push the exhaust curve faster than the standing recipe assumes.

  3. Plan03 / 10

    Simulate three recipes in the fabric twin before committing dye. Prefer the candidate with the lowest predicted ΔE that also fits the 118-minute machine slot.

  4. Action04 / 10

    twin.simulate(recipe_candidates=3, machine="jet-07")

  5. Observation05 / 10

    Candidate B predicts ΔE 0.52 and finishes 6 minutes inside the slot. Candidates A and C either overshoot shade or miss takt.

  6. Decision06 / 10

    Candidate B deviates 7.2% from the standing card, above the 5% autonomy ceiling for dye dosing. Escalate to the colourist rather than act.

  7. Handoff07 / 10

    Dye-and-Color → the colourist on shift, with the simulated curve, the deviation reason and a one-click revert attached.

  8. Action08 / 10

    plc.dose(machine="jet-07", schedule="ramp-B") after approval, with two mid-cycle corrections when exhaustion led the model by 4%.

  9. Observation09 / 10

    Vision flags a 33 m weft streak on roll 09 after finishing. Correlating stenter telemetry shows a pin-chain slip at 04:51, a mechanical cause, not a dye fault.

  10. Outcome10 / 10

    Lot released at mean ΔE 0.58 with 0.22% seconds. A maintenance work order is raised against the stenter pin chain, and the streak signature is added to the mill’s defect memory.

Human in the loop

Craft is captured, not replaced

Textile mills run on scarce craft: the colourist who knows this jet runs hot, the weaving master who hears a beam going wrong. That knowledge is retiring faster than it is being replaced.

Yarneon writes it down. Every approval, override and correction becomes per-mill memory scoped to your tenant, so the mill keeps improving after the person who taught it has gone home.

  • Per-colourist and per-operator performance memory
  • Overrides captured as training signal, not noise
  • Versioned memory, scoped per tenant, never shared across mills

Agent graph

One run, ten steps, one human decision

This is the shape of a dye lot on Yarneon, shown as an illustrative scenario rather than a customer run. Ingest and simulation fan out, converge on a colourist approval gate, then dosing, verification, finishing, inspection and release. The accent traces the active path; every node opens in the inspector.

RUN-4471 10 steps · 1 approval gate · 1 recovered failure · illustrative scenario COMPLETE
ingest conformance twin simulate recipe dye + colour approve human gate dose bath control shade verify ΔE finish stenter inspect vision rework replan grade release

Scroll the graph sideways · or open the text equivalent below

SUCCEEDED APPROVAL FAILED RUNNING
Text equivalent, workflow steps, dependencies and status
Run RUN-4471 workflow graph, as a table
StepStageDepends on StatusDuration
ingestconformancenone SUCCEEDED0.8s
twinsimulateingest SUCCEEDED46s
recipedye + colouringest SUCCEEDED2.4s
approvehuman gatetwin, recipe APPROVAL4m 12s
dosebath controlapprove SUCCEEDED118m
shadeverify ΔEdose SUCCEEDED9.1s
finishstenterdose SUCCEEDED64m
inspectvisionshade, finish FAILED38m
reworkreplaninspect SUCCEEDED1.6s
gradereleaserework SUCCEEDED3.0s
  • Parallel branches2twin simulation and recipe prediction run together
  • Human gates1colourist approval, 15 minutes, attributed
  • Failures recovered1weft streak on roll 09, replanned in-run

Define it in code

Policy is a first-class object

Autonomy level, approval conditions, setpoint envelopes and revert conditions are declared alongside the agent, reviewable in a pull request, not buried in a settings page.

define_dye_agent.py
# Define a bounded dye-control workflow
from yarneon import Mill, Agent, Policy, tools

mill = Mill("mill-02")

dye = Agent(
    name="dye-and-color",
    tools=[
        tools.spectro.read_bath,
        tools.colour.predict_recipe,
        tools.plc.dose(machine="jet-07", mode="bounded"),
    ],
    policy=Policy(
        autonomy="assist",                  # observe | assist | auto
        approve_if="recipe_deviation > 0.05",
        setpoint_limits={"temp_c": (30, 98), "ph": (4.0, 11.5)},
        revert_on="operator_manual",
    ),
)

run = mill.run(dye, goal="lot DL-4471 to 19-4028 TCX, dE <= 0.8")
for step in run.stream():
    print(step.name, step.status, step.duration_ms)
mirror_runs.ts
// Subscribe to run events and mirror them into your MES
const stream = await yarneon.runs.subscribe({
  mill: "mill-02",
  events: ["step.completed", "approval.requested", "defect.detected"]
});

for await (const event of stream) {
  if (event.type === "approval.requested") {
    await mes.raiseApproval({
      lot: event.run.lot,
      reason: event.policy.reason,     // "recipe_deviation 7.2%"
      revertTo: event.policy.lastKnownGood
    });
  }
}

Data handling

What we store, and for how long

Data categories, residency and retention defaults
CategoryResidencyDefault retention
Machine telemetry and setpointsMill edge, mirrored to your region24 months
Inspection framesMill edge by default90 days, configurable
Roll genealogy and conformance recordYour region7 years
Approvals and audit logYour region, append-only7 years
Recipes and chemistryTenant-isolated, never sharedCustomer-controlled

Enterprise

Built for groups, not just for one dyehouse

Multi-site rollout, group benchmarking, governance that a CIO recognises, and deployment options for producers who will never put a dye recipe in someone else’s cloud.

Governance a textile group can actually sign

Approval policies, spend limits, autonomy ceilings and audit exports are configured per site and enforced centrally. Group leadership sees which mill holds shade best on which family, and the mills see why.

  • SSO (SAML/OIDC), SCIM provisioning and RBAC down to the setpoint
  • Per-site data residency, private VPC or fully on-prem deployment
  • Group benchmarking across right-first-time, seconds, water and energy
  • Signed SLAs, named mill engineers and quarterly outcome reviews
  • Outcome-based commercial components on yield, re-dyes and utilities

Group view

One group, one standard

Right-first-time shade by site and shade family, normalised for substrate mix, so a fair comparison is possible for the first time.

Rollout

Shadow first

Wedge line in shadow, then assist, then control.

Autonomy

Per setpoint

Granted one at a time.

Operating figures

The numbers a mill manager asks about second

Latency targets, connector coverage, autonomy modes and the record: the practical questions after the headline.

<100 ms

Design target for a per-frame inspection decision on Jetson-class edge hardware. ASPIRATIONAL

8

Connector families: looms, frames, dyeing, colour, inspection, MES, utilities, robotics.

3

Autonomy modes: observe, assist, bounded control. Granted per setpoint.

1

Record per mill: append-only, exportable, shared with buyers on request.

Items marked ASPIRATIONAL are design targets ahead of production validation.

Questions

Security questions we get asked

Design partners start with one wedge line in shadow mode: connectors and telemetry first, then models scored against what the mill actually produced, then assist mode where the agent proposes and an engineer approves. Whole-mill rollout follows once the wedge holds its numbers. Durations depend on how instrumented the mill already is, so we quote them after the assessment, not before.

Send us your security questionnaire

We answer it honestly, including the parts still in progress. Aspirational items are labelled as such.

Book a mill assessment