Molten metaldoes not forgivea loose system.

Smelteon writes back into furnaces, molding lines, pouring cells and robots. That authority is earned through isolation, grounding, evaluation, bounded windows, approval logs and rollback paths — not asserted in a datasheet.

SOC 2 Type IIIn progress
100%Actions logged
On-premAvailable

Compliance is thefloor, not the story.

Foundry buyers increasingly require grounded, auditable, assurance-grade AI with porosity, defect and casting-genealogy traceability. We build for the audit that follows the escape, not the one that follows the questionnaire.

SOC 2 Type I [in progress]SOC 2 Type II [planned]IATF 16949-alignedISO 9001AS9100NADCAP-awareASTM referencesGDPR-awareSSO / SAMLRBAC

Tenant isolation

Every tenant's telemetry, recipes, geometries and memory are isolated. Retrieval is multi-tenant isolated and permission-aware; memory is versioned and scoped per tenant so the system improves without cross-tenant leakage.

Alloy IP protection

Alloy recipes, gating designs and customer programs are the crown jewels of a foundry. They are never used to serve another tenant, and federated learning shares model priors — never recipes.

Immutable audit log

An assurance-grade record of every agent action, approval, override, escalation and rollback, tied to the casting's genealogy and designed to be exported as audit evidence.

Three gates standbetween a modeland a furnace.

01The process window is law

Every actionable output is checked against a process window authored and approved by a metallurgist or process engineer. A plan outside the window cannot be applied — the SDK does not expose that path.

  • Windows are authored by your engineers
  • Checked on every single move
  • Out-of-window plans escalate, never act
  • Window
  • Approval
  • Rollback

Trust, safetyand evaluation.

The controls that make an agent's output defensible in a quality review.

Grounding and citations

Citation and grounding checks on every output. RAG over melt and sand recipes, gating and solidification specs, casting standards and quality procedures — every recommendation traces to a source.

Continuous evaluation

Golden datasets plus LLM-as-judge evaluation gate every model and prompt change in CI. A regression blocks promotion before it reaches a plant.

Guardrails

Schema and safety guardrails on every agent output, so a malformed or unsafe instruction never reaches a machine connector.

Twin validation

Omniverse-backed scenario tests validate new recipes and control policies before they are promoted to bounded write-back.

Human-in-the-loop

Graduated autonomy with explicit checkpoints. Shadow, then assist, then bounded — each gate opened by evidence, not by schedule.

Attributable actions

Every action carries the model version, the plan, the window, the confidence, the approver and the outcome grade.

What we hold,where, and why.

Process telemetry
Melt, sand, mold, pour, solidification and yield time-series, held per tenant in a time-series store, used to train that tenant's models and (as priors only) federated fleet models.
Inspection media
X-ray, CT, vision and dimensional data, embedded into pgvector for defect retrieval — tenant-isolated, never pooled for another customer's benefit.
Recipes and geometry
Melt and sand recipes, gating and solidification specs and part geometry: treated as customer IP, encrypted, isolated, and excluded from any shared artefact.
Memory
Per-plant yield-and-quality history and per-engineer performance memory, versioned and scoped per tenant and entity.
Audit log
Immutable, append-only record of agent actions and approvals, retained for the contracted evidence period and exportable.
Model artefacts
Fine-tuned models tagged with the tenants whose data trained them; custom alloy and geometry models are never served outside their tenant.

The loop keepsrunning when thenetwork does not.

A foundry cannot pause because a WAN link dropped. Cell inference runs on Jetson beside the PLC and robot controllers, and the model router lives on the factory server — so perception, prediction and bounded control continue locally.

  • Cell-local inference with no inbound cloud dependency
  • Factory-server model router with on-prem fallback armed
  • Staged model promotion with instant rollback to the previous version
  • Degraded modes that fail to observation, never to uncontrolled action

Where we are,and what is next.

0–6 months

Baseline

  • SOC 2 Type I in progress
  • IP-safe deployment patterns documented
  • Security and quality baseline established with design partners

6–12 months

Enterprise-ready

  • SOC 2 Type II
  • SSO and RBAC across the console and API
  • Quality and safety assurance packages for audits

12+ months

Group scale

  • Multi-site evidence models
  • Customer-specific retention and residency options
  • Third-party penetration testing cadence

Tell us somethingand we will act on it.

Vulnerability disclosure

Report suspected vulnerabilities to security@smelteon.com. We acknowledge within one business day and work disclosure timelines with the reporter.

Documentation requests

Security questionnaires, architecture diagrams, data-flow maps and audit evidence requests are handled by the team at security@smelteon.com.

Incident response

Documented incident response with customer notification commitments defined in the enterprise agreement, including OT-specific escalation paths.

The questionnaire,answered early.

No. Recipes, geometries and programs are tenant-isolated and never leave your boundary. Federated fleet learning shares model priors — statistical structure about defects and process windows — and never the recipes or geometry that produced them.

Move a controlled parameter to another point inside a process window your engineers approved, with an approver identity attached, a rollback path armed and the action logged. Anything beyond that is an escalation to a human, not an action.

No. Cell control runs locally on the factory edge. Cloud connectivity is used for training, validation and fleet updates, and the loop continues without it.

Bring us yoursecurity review.

We would rather answer the hard questions before a pilot than during one.