Skip to content

Trust & Compliance

The system of record has to earn the title.

Manufacturers run their factories — and their audits — on Xentr. This page is how we protect the data and the evidence.

Security architecture

Protection that is enforced, not promised.

Each of these is live in the product today — enforced in the database, the application layer or the release pipeline, not in a policy document.

Append-only audit trail

Every change is recorded with who, what, when and the before/after values. Database triggers reject edits and deletes to history — the trail can be exported, never rewritten.

Tenant isolation

Every request is scoped to your organization in the application layer, backed by row-level security policies in the database. Tenant-isolation tests run in CI on every change.

Encryption

TLS protects your data in transit. At rest, it is encrypted on the managed infrastructure we run on.

Invitation-only access

There is no self-signup. Every account is invited, and role-based access control scopes what each of seven roles can see and do.

Secure development

Every change runs through static security analysis (CodeQL) and full-history secret scanning in CI before it ships.

Consent-first analytics

Analytics stay off until you consent — nothing is captured before that, and identifying fields are stripped from events.

Built for audit day

The records the auditor asks for, already kept.

A quality audit runs on evidence. Xentr keeps it as a by-product of running the floor — no binder assembly the week before.

  • Lot and serial traceability, forwards and backwards
  • Inspection records and quality decisions — who reported, who verified
  • Nonconformance reports with root cause and corrective action
  • Downtime and OEE history from the same data the floor produced
  • All of it on an audit trail that cannot be edited

In development

Compliance profiles

Enforcement that switches on per your certification — ISO 9001, ISO 13485, IATF 16949 — chosen at onboarding, so the system requires exactly the evidence your standard does. In development now; ask us where it stands.

Built to the standard

KPIs by ISO 22400, data on open protocols

OEE on Xentr follows the ISO 22400 KPI definitions — setup time never inflates Performance, ideal cycle time comes from your demonstrated best runs, and Availability, Performance and Quality stay honestly separable. The floor connects over open protocols — OPC UA and MQTT, alongside native drivers like FANUC FOCAS — so your data stays portable by design.

Our own program

Where we stand, stated plainly.

Vendors overclaim here constantly. We would rather tell you exactly where we are.

ISO 27001-aligned

Our information-security program is built on ISO/IEC 27001:2022 controls, and we are working toward certification. We publish status honestly — no badge until the certificate exists.

Certified infrastructure

The managed cloud providers we build on hold ISO 27001 and SOC 2 attestations.

Data protection

Our data-protection practices are aligned with Malaysia’s PDPA and the GDPR. The privacy policy spells out what we collect and why.

Paperwork, ready

A data processing agreement and our current sub-processor list are available on request.

Running a security review?

Send us your questionnaire, or bring your IT lead to a walkthrough — we’ll answer everything on this page in depth, with the evidence behind it.

Book a security review