Security & safety
Software that moves a machine has to earn it
Yarneon touches physical process. That raises the bar past normal SaaS security into process safety, OT segmentation and reversibility.
Safety model
Autonomy is granted, never assumed
- Graduated autonomy
- Every workflow moves observe → assist → bounded auto-control. Autonomy ceilings are per-setpoint policy, not a global switch.
- Human-in-the-loop gates
- Approval gates fire on deviation thresholds, new substrates, or any action outside the authorised envelope. Approvals are attributed and time-stamped.
- Reversibility
- Every control action ships with a revert path and a last-known-good setpoint. Operators can take manual control at any moment, from the HMI or the panel.
- Immutable audit log
- Assurance-grade, append-only record of every observation, decision, tool call, approval and actuation, exportable for buyer and regulatory audit.
- Tenant isolation
- Recipes, construction libraries and roll data are isolated per tenant. No cross-tenant training. Permission-aware retrieval with enforced citations.
- Sandboxed tools
- Agents call machines through a typed, scoped tool layer with rate and range limits. There is no path from a model output to an unbounded PLC write.
- Deployment choice
- Cloud, private VPC or fully on-prem via NVIDIA AI Enterprise for groups protecting dye-recipe IP. Data residency selectable per site.
- Access control
- SSO (SAML/OIDC), SCIM provisioning, RBAC down to workflow and setpoint, and break-glass procedures with mandatory review.
Compliance posture
The certifications buyers and auditors ask for
Textile buyers audit chemistry, labour and traceability. Enterprise IT audits everything else. Both get evidence rather than assurances.
-
SOC 2 Type I
In progress ASPIRATIONAL, Type II planned -
ISO 27001
In progress ASPIRATIONAL -
GDPR
Aligned -
IEC 62443
OT security alignment -
ZDHC MRSL
Reporting supported -
OEKO-TEX / bluesign
Evidence export
Items marked ASPIRATIONAL are in progress and are stated as such deliberately. We would rather be boring about this than surprising.
OT posture
How we sit on your network
The edge appliance is the boundary
Yarneon does not put your PLCs on the internet. The appliance sits in a segmented cell, speaks to controllers over OPC UA and vendor protocols, and exposes nothing inbound.
- Outbound-only mutual TLS; no inbound ports on the mill network
- Purdue-model aware placement with a documented data diode option
- Signed firmware and model artefacts, verified on load
- Local operation with full function when the link is down
- Per-tenant key isolation; models never trained across customers
Failure mode
Loses the internet, keeps the mill
If the uplink drops, the edge appliance keeps running the loop with local models and buffers the record until it can sync.
Override
One button
At the machine panel.
Audit
Immutable
Append-only, exportable.
Tool-call stream
Every call the agent made, in order
Machines, spectrophotometers, the optimiser and the humans are all tools. Calls go out, results come back, and the whole exchange is real, copyable text, the same record your auditor sees.
Guardrail in action
policy.check → requires human approval
At 04:03:04 the proposed recipe deviated 7.2% from the standing card, above the 5% autonomy ceiling for dye dosing at this mill. The agent stopped and asked. Fifteen minutes later a colourist approved it, and that approval is attributed, timestamped and reversible.
Failure handled honestly
vision.scan → WEFT_STREAK, roll 09
A 33 m weft streak is a real defect, and the run shows it as failed rather than smoothing it over. The mechanical root cause, a stenter pin-chain slip, was correlated automatically and raised as a work order.
Reasoning trace
The reasoning, written down
Goal, observation, plan, action, decision, handoff, outcome. A colourist can read this and disagree with it, which is the point. Autonomy a mill cannot argue with is autonomy a mill will not adopt.
-
Land DL-4471 on Indigo 19-4028 TCX within ΔE 0.80, first time, before the Thursday 06:00 ship cut-off.
-
Greige absorbency for this lot reads 8% above the card baseline, and incoming water hardness is 142 ppm, both push the exhaust curve faster than the standing recipe assumes.
-
Simulate three recipes in the fabric twin before committing dye. Prefer the candidate with the lowest predicted ΔE that also fits the 118-minute machine slot.
-
twin.simulate(recipe_candidates=3, machine="jet-07")
-
Candidate B predicts ΔE 0.52 and finishes 6 minutes inside the slot. Candidates A and C either overshoot shade or miss takt.
-
Candidate B deviates 7.2% from the standing card, above the 5% autonomy ceiling for dye dosing. Escalate to the colourist rather than act.
-
Dye-and-Color → the colourist on shift, with the simulated curve, the deviation reason and a one-click revert attached.
-
plc.dose(machine="jet-07", schedule="ramp-B") after approval, with two mid-cycle corrections when exhaustion led the model by 4%.
-
Vision flags a 33 m weft streak on roll 09 after finishing. Correlating stenter telemetry shows a pin-chain slip at 04:51, a mechanical cause, not a dye fault.
-
Lot released at mean ΔE 0.58 with 0.22% seconds. A maintenance work order is raised against the stenter pin chain, and the streak signature is added to the mill’s defect memory.
Human in the loop
Craft is captured, not replaced
Textile mills run on scarce craft: the colourist who knows this jet runs hot, the weaving master who hears a beam going wrong. That knowledge is retiring faster than it is being replaced.
Yarneon writes it down. Every approval, override and correction becomes per-mill memory scoped to your tenant, so the mill keeps improving after the person who taught it has gone home.
- Per-colourist and per-operator performance memory
- Overrides captured as training signal, not noise
- Versioned memory, scoped per tenant, never shared across mills
Agent graph
One run, ten steps, one human decision
This is the shape of a dye lot on Yarneon, shown as an illustrative scenario rather than a customer run. Ingest and simulation fan out, converge on a colourist approval gate, then dosing, verification, finishing, inspection and release. The accent traces the active path; every node opens in the inspector.
Scroll the graph sideways · or open the text equivalent below
Text equivalent, workflow steps, dependencies and status
| Step | Stage | Depends on | Status | Duration |
|---|---|---|---|---|
| ingest | conformance | none | SUCCEEDED | 0.8s |
| twin | simulate | ingest | SUCCEEDED | 46s |
| recipe | dye + colour | ingest | SUCCEEDED | 2.4s |
| approve | human gate | twin, recipe | APPROVAL | 4m 12s |
| dose | bath control | approve | SUCCEEDED | 118m |
| shade | verify ΔE | dose | SUCCEEDED | 9.1s |
| finish | stenter | dose | SUCCEEDED | 64m |
| inspect | vision | shade, finish | FAILED | 38m |
| rework | replan | inspect | SUCCEEDED | 1.6s |
| grade | release | rework | SUCCEEDED | 3.0s |
- Parallel branches2twin simulation and recipe prediction run together
- Human gates1colourist approval, 15 minutes, attributed
- Failures recovered1weft streak on roll 09, replanned in-run
Define it in code
Policy is a first-class object
Autonomy level, approval conditions, setpoint envelopes and revert conditions are declared alongside the agent, reviewable in a pull request, not buried in a settings page.
# Define a bounded dye-control workflow
from yarneon import Mill, Agent, Policy, tools
mill = Mill("mill-02")
dye = Agent(
name="dye-and-color",
tools=[
tools.spectro.read_bath,
tools.colour.predict_recipe,
tools.plc.dose(machine="jet-07", mode="bounded"),
],
policy=Policy(
autonomy="assist", # observe | assist | auto
approve_if="recipe_deviation > 0.05",
setpoint_limits={"temp_c": (30, 98), "ph": (4.0, 11.5)},
revert_on="operator_manual",
),
)
run = mill.run(dye, goal="lot DL-4471 to 19-4028 TCX, dE <= 0.8")
for step in run.stream():
print(step.name, step.status, step.duration_ms)
// Subscribe to run events and mirror them into your MES
const stream = await yarneon.runs.subscribe({
mill: "mill-02",
events: ["step.completed", "approval.requested", "defect.detected"]
});
for await (const event of stream) {
if (event.type === "approval.requested") {
await mes.raiseApproval({
lot: event.run.lot,
reason: event.policy.reason, // "recipe_deviation 7.2%"
revertTo: event.policy.lastKnownGood
});
}
}
Data handling
What we store, and for how long
| Category | Residency | Default retention |
|---|---|---|
| Machine telemetry and setpoints | Mill edge, mirrored to your region | 24 months |
| Inspection frames | Mill edge by default | 90 days, configurable |
| Roll genealogy and conformance record | Your region | 7 years |
| Approvals and audit log | Your region, append-only | 7 years |
| Recipes and chemistry | Tenant-isolated, never shared | Customer-controlled |
Enterprise
Built for groups, not just for one dyehouse
Multi-site rollout, group benchmarking, governance that a CIO recognises, and deployment options for producers who will never put a dye recipe in someone else’s cloud.
Governance a textile group can actually sign
Approval policies, spend limits, autonomy ceilings and audit exports are configured per site and enforced centrally. Group leadership sees which mill holds shade best on which family, and the mills see why.
- SSO (SAML/OIDC), SCIM provisioning and RBAC down to the setpoint
- Per-site data residency, private VPC or fully on-prem deployment
- Group benchmarking across right-first-time, seconds, water and energy
- Signed SLAs, named mill engineers and quarterly outcome reviews
- Outcome-based commercial components on yield, re-dyes and utilities
Group view
One group, one standard
Right-first-time shade by site and shade family, normalised for substrate mix, so a fair comparison is possible for the first time.
Rollout
Shadow first
Wedge line in shadow, then assist, then control.
Autonomy
Per setpoint
Granted one at a time.
Operating figures
The numbers a mill manager asks about second
Latency targets, connector coverage, autonomy modes and the record: the practical questions after the headline.
Design target for a per-frame inspection decision on Jetson-class edge hardware. ASPIRATIONAL
Connector families: looms, frames, dyeing, colour, inspection, MES, utilities, robotics.
Autonomy modes: observe, assist, bounded control. Granted per setpoint.
Record per mill: append-only, exportable, shared with buyers on request.
Items marked ASPIRATIONAL are design targets ahead of production validation.
Questions
Security questions we get asked
Send us your security questionnaire
We answer it honestly, including the parts still in progress. Aspirational items are labelled as such.