Per-tenant everything
Data, models, retrieval indexes and memory are scoped per tenant and per entity. On-prem deployment is available for sensitive producers.
Security & trust
Once on information security, and once on process safety. Extruon is built for both: per-tenant isolation and strict die-IP protection on one side, bounded envelopes, interlocks and immutable audit on the other.
Assurance-grade by default
Extruon never asks for control it has not earned. Shadow mode proves accuracy against your operators and gauges; advisory mode proves ROI; bounded autonomy only follows once the gates are met.
Data, models, retrieval indexes and memory are scoped per tenant and per entity. On-prem deployment is available for sensitive producers.
Die designs, customer drawings and recipes never leave your boundary. Fleet learning shares defect signatures and process priors, never geometry.
Every perception, recommendation, approval and setpoint write is recorded with its evidence, ready for quality and customer audits.
SSO and role-based access, encryption in transit and at rest, SOC 2 programme in progress, and fail-safe interlocks on every write path.
Information security
SAML/OIDC single sign-on with role-based access control, down to who may approve a setpoint write on which press.
Encryption in transit and at rest across edge, control plane and storage, with per-tenant key scoping.
Data, models, retrieval indexes and memory scoped per tenant and per entity, with permission-aware retrieval filtering.
Full on-premise deployment for producers who cannot send process data off site, with the same feature set.
SOC 2 Type I in progress and Type II targeted as the security baseline matures alongside enterprise deployments. [ASPIRATIONAL]
OpenTelemetry tracing across agent steps, model calls and write paths, with per-tenant log separation.
Die IP
Die designs, customer drawings and press recipes are the most sensitive assets an extruder owns. They are also the assets a naive fleet-learning system would leak first.
Anonymised defect signatures · aggregate process priors · model gradients under opt-in cohorts
Die geometry and CAD · customer drawings · press recipes · order book · plant performance · quality records · operator identity
Fleet-learning participation is opt-in per cohort and revocable at any time.
Process safety
Four independent mechanisms, any one of which can stop a move. None of them depend on the cloud.
Min, max and max-step per writable setpoint, defined by your engineers and enforced at the edge before anything reaches the PLC.
Human-in-the-loop approval required for high-impact, high-force-press and temper decisions, configurable per press.
Any alarm reverts the last move and returns control to the existing fail-safe stop for press, quench, saw and robots.
Model and policy promotions must pass twin validation and golden-dataset evaluation in CI before reaching a live press.
Agent steps are idempotent, so a retry after a network blip never applies a setpoint move twice.
If perception degrades — a camera fails, a gauge drops out — the affected agent falls back to advisory rather than acting on partial truth.
The write path
Nothing reaches the press without passing the envelope, the approval policy and the guardrail — and nothing passes without leaving an immutable record of what it saw and why it acted.
The audit trail is designed for quality and customer audits, not just internal debugging.
Audit trail
| Field | Example | Why it matters |
|---|---|---|
| Perception snapshot | Frames, thermal field, gauge trace at decision time | Reconstruct what the system actually saw |
| Model & version | defect-vit v14 · flow-pinn v7 | Attribute an outcome to a specific model build |
| Proposal & rationale | ram_speed +0.3 mm/s · die-line risk 0.31→0.18 | Explain the trade the orchestrator made |
| Envelope check | within min 4.0 / max 8.5 / step 0.4 | Prove the move was inside the approved bounds |
| Approver | process-engineer · auto (bounded) | Establish accountability for the decision |
| Outcome | wall dev ±0.05 mm · recovery 88.1% · no defect | Close the loop between decision and result |
Evaluation
Every model and prompt change is scored against golden datasets of labelled pushes, defects and temper outcomes.
Reasoning and knowledge outputs are graded for grounding, citation validity and schema compliance.
Control policy changes are swept in the press-and-die twin across billet temperature, speed, die temperature and quench.
Promotion to shadow, then assist, then bounded autonomy — per press, with instant rollback and full logging.
Security FAQ
Plant-edge first. Perception, inference, envelopes and interlocks run on site. Cloud is used for training, fleet analytics and model distribution, and can be removed entirely with an on-prem deployment.
Yes, in on-prem mode. Model updates then arrive through your own controlled channel rather than an OTA link.
Fleet learning is opt-in per cohort and shares anonymised defect signatures and aggregate process priors only. Die geometry, drawings, recipes, customers and plant performance never leave your boundary.
Only a role you designate, per press and per setpoint, with envelopes your engineers define. Enabling write-back is an explicit, logged, reversible action.
The affected agent degrades to advisory. Extruon does not act on partial perception, and the degradation is visible in the console and the audit trail.
SOC 2 Type I is in progress with Type II targeted as enterprise deployments mature. [ASPIRATIONAL] Current controls, policies and the security pack are available under NDA on request.
Measured on the press
Every Extruon engagement starts with a baseline and ends with an audited delta. These are the target bands we underwrite in a paid pilot.
+4.2 pts
Press recovery uplift, saleable vs charged metal
−38%
Surface-defect and dimensional rejects
−61%
Die-trial pushes before a die is signed off
−12%
kWh per tonne across heating, quench and aging
Target outcome bands modelled from design-partner baselines. [ASPIRATIONAL — to be replaced with audited pilot results.]
Security
Request the security pack, the architecture diagram and the audit-log schema. We would rather answer hard questions early than late.
Land on one press. Expand press by press, module by module, site by site.