Trust and evidence

Make the operating record as clear as the operating alert.

ciliot is designed around precise, reviewable controls: tenant-aware authorization, source-aware evidence, contextual workflows, and clear limits. We do not present those controls as an absolute guarantee or a shortcut to a customer’s compliance responsibilities.

A disciplined foundation

Trust is visible in the way the service handles context, not a badge.

Security, resilience, data governance, and operating evidence need to be designed into the product and reviewed in the customer’s actual environment. The public summary below explains the intended approach—not a certification or universal claim.

Authorization in context

Use tenant, role, entitlement, and support-access boundaries so people have the scope required for their operational responsibility.

Evidence with lineage

Retain source, event-time, configuration, calibration, response, and report context so the scope of a record can be reviewed.

Resilience made explicit

Design for the reality of device, power, gateway, and connectivity disruption; surface gaps rather than hiding them.

Data as operational evidence

Explain the provenance and quality of a condition before asking a team to act.

In cold-chain operations, an in-range reading is not by itself a compliance conclusion. A useful record makes its source, calibration, applicable regime, timing, completeness, and response history clear to the reviewer.

  • Source preservedPreserve raw device evidence separately from canonical and derived service records.
  • Quality visibleRepresent late, missing, duplicate, out-of-order, or otherwise qualified data as part of the operating context.
  • Scope retainedAssociate the approved policy, assets, people, and response evidence with the resulting condition.

What a review needs

Evidence does not need to be opaque to be useful.

  • What was received, when it was observed, and from which device or gateway source.
  • Which configuration, temperature regime, and calibration state applied at the time.
  • Who was notified, who took ownership, and which response actions were recorded.
  • Which gaps, assumptions, or limitations a reviewer must still take into account.

Privacy and service boundaries

Collect only what an operating service needs and keep the boundary reviewable.

Refrigeration telemetry may become personal data when it is associated with users, support actions, vehicle routes, or future people-sensing services. Customer deployment needs to define data classes, owners, retention, locations, and access boundaries.

Purpose and minimisation

Collect, display, and retain the data needed for the agreed service purpose; do not use a marketing surface to expose customer or operational data.

Roles and accountability

Identify the tenant administrator, security/IT owner, service owner, support path, and escalation contacts before operating a production service.

Review and change

Assess new data types, integrations, camera/audio/biometric features, locations, and retention changes through the appropriate governance process.

Claims governance

Say only what the current evidence can support.

Product, performance, security, customer, and commercial claims require current evidence and named approval before publication.

What can ciliot say about product capability?

Only what a released feature and current service documentation support, with confirmation from the accountable product owner.

What does a performance or reliability claim require?

A defined methodology, environment, period, and independently reviewable result. We do not generalise a result beyond its stated scope.

What does a savings or ROI claim require?

A customer-specific baseline, formula version, period, approval, and written permission. A generic savings percentage is not an approved ciliot claim.

What does a security or compliance claim require?

Formal scope and evidence, an expiration or renewal date, and legal/security approval. Product controls do not themselves confer regulatory compliance.

Bring your requirements

Start with the evidence, privacy, and operating controls your team needs.

A pilot conversation can make the customer-specific boundaries, responsibilities, and review criteria explicit before a production commitment.

Request a pilot conversation