Trust & Compliance
The system of record has to earn the title.
Manufacturers run their factories — and their audits — on Xentr. This page is how we protect the data and the evidence.
Security architecture
Protection that is enforced, not promised.
Each of these is live in the product today — enforced in the database, the application layer or the release pipeline, not in a policy document.
Append-only audit trail
Every change is recorded with who, what, when and the before/after values. Database triggers reject edits and deletes to history — the trail can be exported, never rewritten.
Tenant isolation
Every request is scoped to your organization in the application layer, backed by row-level security policies in the database. Tenant-isolation tests run in CI on every change.
Encryption
TLS protects your data in transit. At rest, it is encrypted on the managed infrastructure we run on.
Invitation-only access
There is no self-signup. Every account is invited, and role-based access control scopes what each of seven roles can see and do.
Secure development
Every change runs through static security analysis (CodeQL) and full-history secret scanning in CI before it ships.
Consent-first analytics
Analytics stay off until you consent — nothing is captured before that, and identifying fields are stripped from events.
Built for audit day
The records the auditor asks for, already kept.
A quality audit runs on evidence. Xentr keeps it as a by-product of running the floor — no binder assembly the week before.
- Lot and serial traceability, forwards and backwards
- Inspection records and quality decisions — who reported, who verified
- Nonconformance reports with root cause and corrective action
- Downtime and OEE history from the same data the floor produced
- All of it on an audit trail that cannot be edited
In development
Compliance profiles
Enforcement that switches on per your certification — ISO 9001, ISO 13485, IATF 16949 — chosen at onboarding, so the system requires exactly the evidence your standard does. In development now; ask us where it stands.
Built to the standard
KPIs by ISO 22400, data on open protocols
OEE on Xentr follows the ISO 22400 KPI definitions — setup time never inflates Performance, ideal cycle time comes from your demonstrated best runs, and Availability, Performance and Quality stay honestly separable. The floor connects over open protocols — OPC UA and MQTT, alongside native drivers like FANUC FOCAS — so your data stays portable by design.
Our own program
Where we stand, stated plainly.
Vendors overclaim here constantly. We would rather tell you exactly where we are.
ISO 27001-aligned
Our information-security program is built on ISO/IEC 27001:2022 controls, and we are working toward certification. We publish status honestly — no badge until the certificate exists.
Certified infrastructure
The managed cloud providers we build on hold ISO 27001 and SOC 2 attestations.
Data protection
Our data-protection practices are aligned with Malaysia’s PDPA and the GDPR. The privacy policy spells out what we collect and why.
Paperwork, ready
A data processing agreement and our current sub-processor list are available on request.
Running a security review?
Send us your questionnaire, or bring your IT lead to a walkthrough — we’ll answer everything on this page in depth, with the evidence behind it.
