1. Security approach
AICAN designs Optiwise to protect operational manufacturing data while keeping workflows usable for real factory teams. Our security approach focuses on controlled access, secure infrastructure, auditability, reliable backups, careful vendor usage, and practical safeguards for mobile and shopfloor environments.
2. Data handled by Optiwise
Depending on the modules a customer uses, Optiwise may process sales, CRM, purchase, inventory, production, quality, dispatch, task, report, document, user, approval, mobile, IoT, and machine data. Customers choose what data to enter, upload, connect, import, or sync into the platform.
3. Access control
- Role-based access controls help limit users to the modules, actions, documents, and records they need.
- Customer administrators can manage user invitations, roles, permissions, and deactivation.
- Sensitive actions may be protected through approval workflows, audit trails, and permission checks.
- Users are expected to use strong passwords, secure devices, and company-approved account practices.
4. Encryption and data protection
We use modern transport security for data moving between users and the platform. Infrastructure, database, storage, and backup protections are selected to reduce unauthorized access, loss, and misuse. Specific encryption, hosting, retention, or compliance commitments may be defined in a signed customer agreement where required.
5. Infrastructure and hosting
AICAN uses reputable infrastructure and service providers for hosting, storage, monitoring, communications, and operational services. Access to production systems is restricted to authorized personnel and service providers who need it for operation, support, maintenance, security, or legal reasons.
6. Auditability and traceability
- Optiwise can maintain operational history for records, workflow status, approvals, tasks, documents, and activity where the module supports it.
- Audit trails help teams understand who changed what, when a status moved, and where a decision or exception came from.
- Traceability depends on customer configuration, user discipline, integrations, and data quality.
7. Backups and continuity
We maintain backup and recovery practices intended to reduce data loss and restore service after operational issues. Backup frequency, retention, recovery objectives, and custom disaster recovery commitments may vary by plan, deployment, and signed agreement.
8. AI and data security
AI features are used to support workflows such as summaries, alerts, recommendations, anomaly detection, forecasting, search, and natural-language answers. AI outputs are generated from available data and permissions. Customers should review outputs before using them for operational, commercial, safety, or compliance decisions.
9. Mobile app security
- Mobile users should keep devices locked, updated, and protected from unauthorized access.
- Camera, microphone, files, photos, and notifications are used only for enabled workflow features such as QR scanning, document upload, proof capture, voice entries, and alerts.
- Lost-device or employee-exit scenarios should be handled quickly by removing the user's access from the workspace.
10. IoT and shopfloor security
Shopfloor connectivity depends on secure installation, network configuration, device maintenance, and customer plant practices. Customers are responsible for safe installation, electrical safety, physical device security, local network segmentation, calibration, and machine-safety procedures. AICAN can provide guidance for supported deployments.
11. Vendor and employee access
AICAN limits internal and vendor access to customer environments based on business need. Support, engineering, infrastructure, and security personnel may access limited data or systems when required to provide support, troubleshoot issues, maintain the service, investigate abuse, or comply with law.
12. Incident response
If we identify a security incident that affects customer data, we will investigate, contain, and communicate as appropriate under the applicable agreement and law. Customers should promptly report suspected unauthorized access, lost devices, unusual activity, or security concerns.
13. Customer responsibilities
- Assign correct roles and remove access when team members leave or change responsibilities.
- Keep company devices, browsers, phones, tablets, shopfloor terminals, and local networks secure.
- Review integration permissions and connected third-party tools.
- Maintain accurate master data, workflows, approvals, machine mappings, and user records.
- Train users to handle business data, documents, QR codes, voice entries, and operational approvals responsibly.
14. Certifications and custom reviews
AICAN can support customer security reviews and vendor onboarding questionnaires. We do not claim a security certification unless it is separately stated in official AICAN materials or a signed customer document.
15. Contact security
To report a security issue or ask about data protection, contact vedant@aican.co.in with the subject line Security Concern.
