Tenant isolation
Every tenant's telemetry, recipes, geometries and memory are isolated. Retrieval is multi-tenant isolated and permission-aware; memory is versioned and scoped per tenant so the system improves without cross-tenant leakage.
Smelteon writes back into furnaces, molding lines, pouring cells and robots. That authority is earned through isolation, grounding, evaluation, bounded windows, approval logs and rollback paths — not asserted in a datasheet.
Foundry buyers increasingly require grounded, auditable, assurance-grade AI with porosity, defect and casting-genealogy traceability. We build for the audit that follows the escape, not the one that follows the questionnaire.
Every tenant's telemetry, recipes, geometries and memory are isolated. Retrieval is multi-tenant isolated and permission-aware; memory is versioned and scoped per tenant so the system improves without cross-tenant leakage.
Alloy recipes, gating designs and customer programs are the crown jewels of a foundry. They are never used to serve another tenant, and federated learning shares model priors — never recipes.
An assurance-grade record of every agent action, approval, override, escalation and rollback, tied to the casting's genealogy and designed to be exported as audit evidence.
Every actionable output is checked against a process window authored and approved by a metallurgist or process engineer. A plan outside the window cannot be applied — the SDK does not expose that path.
The controls that make an agent's output defensible in a quality review.
Citation and grounding checks on every output. RAG over melt and sand recipes, gating and solidification specs, casting standards and quality procedures — every recommendation traces to a source.
Golden datasets plus LLM-as-judge evaluation gate every model and prompt change in CI. A regression blocks promotion before it reaches a plant.
Schema and safety guardrails on every agent output, so a malformed or unsafe instruction never reaches a machine connector.
Omniverse-backed scenario tests validate new recipes and control policies before they are promoted to bounded write-back.
Graduated autonomy with explicit checkpoints. Shadow, then assist, then bounded — each gate opened by evidence, not by schedule.
Every action carries the model version, the plan, the window, the confidence, the approver and the outcome grade.
A foundry cannot pause because a WAN link dropped. Cell inference runs on Jetson beside the PLC and robot controllers, and the model router lives on the factory server — so perception, prediction and bounded control continue locally.
0–6 months
6–12 months
12+ months
Report suspected vulnerabilities to security@smelteon.com. We acknowledge within one business day and work disclosure timelines with the reporter.
Security questionnaires, architecture diagrams, data-flow maps and audit evidence requests are handled by the team at security@smelteon.com.
Documented incident response with customer notification commitments defined in the enterprise agreement, including OT-specific escalation paths.
No. Recipes, geometries and programs are tenant-isolated and never leave your boundary. Federated fleet learning shares model priors — statistical structure about defects and process windows — and never the recipes or geometry that produced them.
Move a controlled parameter to another point inside a process window your engineers approved, with an approver identity attached, a rollback path armed and the action logged. Anything beyond that is an escalation to a human, not an action.
No. Cell control runs locally on the factory edge. Cloud connectivity is used for training, validation and fleet updates, and the loop continues without it.
We would rather answer the hard questions before a pilot than during one.