Skip to content
Secure cloud and engineering data environment for HAZOP analysis with data protection and compliance context

Security & Compliance

Data sovereignty, documented processing and transparent AI support.

Safety-critical software is reviewed not only by users, but also by IT, data protection, procurement and management. This page answers key questions on data hosting, access, AI support and contractual documentation.

[ 00 ] Data sovereignty

Your engineering data stays protected

Security concept for sensitive engineering and process data.

Hosting, encryption, access control and traceability for sensitive plant information.

HAIZOP is designed for sensitive engineering data. The core platform is operated in a documented EU cloud environment. Tenant isolation, role-based access control, multi-factor protection and an audit trail support controlled and traceable use.

EU cloud location
Private deployment by separate agreement
Encryption
Roles, multi-factor protection and audit trail
Security visualisation with cloud infrastructure, access control and protected engineering data

[ 01 ] Data hosting

Core platform and customer data are operated in Europe

Data sovereignty is not an add-on.

EU cloud environment

Platform, application database and file uploads are operated in the documented EU cloud environment. AI services, email delivery and other service providers are governed by contractually documented subprocessors and third-country rules.

Private-deployment assessment

For special security requirements, a separate deployment model can be individually assessed. Such a solution is not part of the standard offer and requires a separate agreement.

DPA/TOMs under GDPR

Data processing, technical and organisational measures, subprocessors, third-country transfers, deletion periods and export options are documented contractually.

Tenant isolation

Customer data is processed by organisation and tenant. Customer data is not used to train AI models unless expressly agreed separately.

EU data hosting, tenant separation and protected engineering documents in the HAIZOP platform
AI transparency with human review, review status and traceable suggestions

[ 02 ] AI transparency

Transparent AI support

AI support is made recognisable.

AI labelling

AI-generated content is treated as suggestions and made recognisable in the platform where it appears in the respective workflow. User actions, review states and changes are traceably supported through the audit trail.

AI transparency documented

Visible uncertainty

The platform supports users in marking open, incomplete or review-required content. Review status, comments and notes help document expert checks traceably.

Expert review

AI outputs do not replace expert review. They are suggestions and must be reviewed, accepted, adapted or rejected by qualified users. Responsibility for assessment, approval and use of results remains with the customer.

Traceability

Where technically available, the platform shows context information, assumptions and underlying notes. This supports expert review of suggestions.

[ 04 ] Platform security functions

Multi-user operation with roles and traceable changes

Core security functions for platform operation.

Role-based access control

Observer, reviewer, engineer and administrator roles support role-based access control according to the agreed licence model and technical configuration.

Two-factor authentication

Multi-factor authentication can be used to add protection for user accounts. Details depend on technical availability and configuration.

SSO by separate agreement

Integration with customer-side identity providers can be assessed and individually agreed for separately agreed use cases.

Audit trail for key actions

Key actions and changes are logged with user reference, timestamp and further technical metadata where provided by the system.

Encryption

Passwords, sessions, secrets and security-relevant system components are protected through appropriate technical safeguards.

Rate limiting & CSRF protection

The platform uses safeguards against misuse, unauthorised sessions and common web attacks.

Platform controls with roles, two-factor authentication, audit trail and access protection