Security and controls

Control what Service Spine can see and who approves the brief.

For a pilot, the customer identifies the records Service Spine may use and the employee who reviews the output. Before any production connection, the deployment, access and data handling are documented with the customer.

Access

Only the records needed for the selected workflow.

Service Spine access scope
Company playbookGeneral operating rulesAvailable to all employees.
Personnel recordsCompensation and employee dataAvailable only to Human Resources.
Assigned accountsRelevant sites, equipment and historyAvailable to the assigned team and senior technicians.
Broad service historyAccounts within authorized responsibilityAvailable only to senior technicians.

Illustrative access model. Final controls depend on the production deployment and are documented before connection.

During a pilot

Three controls keep the work focused.

01

Agreed records

The customer identifies the records needed for the selected workflow. Other systems stay outside the pilot.

02

Sources attached

Each finding keeps its source reference so the reviewer can check the work.

03

Employee approval

Service Spine prepares the brief. An employee decides what happens next.

Current limits

Public website

Separate from customer systems

This website is not connected to a contractor’s monitoring, ERP, field-service or inspection systems. The inquiry form stores only the details a visitor submits for follow-up.

Pilot

One workflow at a time

The written scope lists the records, people, output and measure for the pilot. Expanding it requires a separate decision.

System changes

No assumed write access

A draft next step does not authorize a change in an operating system. Any write access would have to be defined and approved separately.

Claims

Only what can be verified

We do not claim a certification, audit result or control that has not been completed for the deployment under review.

Before production

We document the actual deployment.

Hosting and region

The provider, processing region and path taken by customer data.

Encryption

How data is protected in transit and at rest, including responsibility for key management.

Model use

Which model providers are involved and the terms governing storage, use and training.

Retention and deletion

What is retained, for how long, how deletion works and who can request it.

Boundaries and logging

How customer data is separated, how access is recorded and how exceptions are handled.

These decisions depend on the architecture selected with the customer. The final documentation describes that deployment.

Talk through a service problem