Security & guardrails

An agent that can move a nip needs more than a good model.

Pulpum writes to production equipment on machines that run at 1,200 metres a minute. Security here is not only about data — it is about what the software is permitted to do, under what conditions, with whose approval, and what happens when something fails.

IEC 62443 alignedSOC 2 Type II in progressAir-gapped option

run_8f21c4 · agent graph · PM4 10 nodes · 1 approval gate
01 · orchestrator ingest.grade_target ✓ SUCCEEDED 02 · orchestrator twin.simulate ✓ SUCCEEDED 03 · pulp_stock stock.refine ✓ SUCCEEDED 04 · wetend_chem wetend.dose ✓ SUCCEEDED 05 · form_press form.headbox ✓ SUCCEEDED 06 · form_press press.nip ✓ SUCCEEDED 07 · dry_coat dry.steam ✓ SUCCEEDED 08 · defect_inspect inspect.web ✓ SUCCEEDED 09 · orchestrator approve.human ◆ APPROVAL 10 · quality_conf reel.qualify ✓ SUCCEEDED

Live example: Grade change PM4 · 135 gsm kraftliner → 110 gsm testliner, no break, ≤14 min off-spec

Defence in depth

Six layers between a model and a setpoint

A recommendation has to survive all six before it reaches the DCS.

Layer 01

Bounded action space

Each agent has an explicit tag allow-list. A tag not on the list cannot be written, regardless of what any model outputs.

Layer 02

Unit-aware limits

Every tool declares magnitude and rate limits in engineering units. A 0.15 bar per 30 s limit is enforced at call time, not reviewed later.

Layer 03

Twin verification

Moves are simulated before execution. A move that raises modelled break risk above the site limit is discarded.

Layer 04

Policy engine

Autonomy level, grade, shift, interlock state and operator presence are all evaluated before the write is released.

Layer 05

Human approval

Anything above the site risk threshold waits for a named approver, with the request and reasoning shown in mill units.

Layer 06

Audit and reversal

Every write is logged with its full context and can be reverted to the prior known-good value in one action.

Tool calls

Every call, on the record

This is the actual log format: timestamp, tool, arguments, result. Copyable, exportable, hash-chained.

tool-call stream · run_8f21c4
  1. 04:51:04mes.read_orders({ machine: "PM4", next_grade: "TL-110" })
  2. 04:51:04ok spec locked · basis 110 g/m² · moisture 7.4% ±0.5
  3. 04:51:05twin.simulate({ candidates: 48, horizon: "18 min" })
  4. 04:51:39ok best recipe #31 · est. off-spec 6.4 t · break risk 0.07
  5. 04:51:40policy.evaluate({ recipe: 31, autonomy: "L3" })
  6. 04:51:40ok 9 writes permitted · 1 write requires human approval
  7. 04:51:41dcs.write_setpoint({ tag: "REF4.SEL", from: 1.9, to: 1.4 })
  8. 04:53:51ok freeness 388 → 412 CSF · consistency 3.4%
  9. 04:53:52chem.dose({ retention_aid: "214 g/t", sizing: "1.1 kg/t" })
  10. 04:55:18ok first-pass retention 71% → 78%
  11. 04:55:19dcs.slice_profile({ actuators: 78, jet_to_wire: 0.994 })
  12. 04:56:24ok formation index 84 · CD basis 2σ 1.7 g/m²
  13. 04:56:25vision.stream({ cameras: 18, model: "webdefect-v7" })
  14. 04:56:41precursor: edge crack risk 0.62 · drive side · 1,412 mm
  15. 04:56:42dcs.nip_load({ delta: "-40 kN/m", zone: "press-2" })
  16. 04:56:58ok edge crack risk 0.62 → 0.09 · web stable
  17. 04:56:59approval.request({ action: "speed_ramp", to: "1245 m/min" })
  18. 04:57:12ok approved by J. Okonkwo (machine tender) · logged
  19. 04:58:44mes.log_reel({ reel: "R-24188", genealogy: "full" })
  20. 05:02:46ok run complete · 11m42s · off-spec 6.2 t · breaks 0

Reasoning trace

Plan → thought → action → observation, exactly as the orchestrator recorded it.

GoalMove PM4 from 135 gsm kraftliner to 110 gsm testliner with zer…

Move PM4 from 135 gsm kraftliner to 110 gsm testliner with zero breaks and under 14 minutes of off-spec production.

PlanSimulate the transition on the twin first. Lead with stock and…

Simulate the transition on the twin first. Lead with stock and chemistry so the furnish is right before the basis weight ramps, then trim forming and press, then re-phase drying. Watch the web continuously; hold the speed ramp for a human.

ThoughtThe standing recipe drops basis weight and speed together. On …

The standing recipe drops basis weight and speed together. On the twin that produces a 3-minute moisture excursion because the dryer section unloads faster than the steam schedule can follow. Sequencing the steam re-phase ahead of the basis-weight ramp removes it.

Actiontwin.simulate(candidates=48) → recipe #31 re-phases steam 40 s…

twin.simulate(candidates=48) → recipe #31 re-phases steam 40 s before the basis-weight ramp and holds nip load until post-press dryness confirms.

ObservationRecipe #31 estimates 6.4 t off-spec against 9.8 t for the stan…

Recipe #31 estimates 6.4 t off-spec against 9.8 t for the standing recipe, with break risk 0.07. Two candidates scored lower on steam but raised break risk above the 0.15 site limit and were discarded.

ActionExecute recipe #31 under autonomy level L3: nine setpoint writ…

Execute recipe #31 under autonomy level L3: nine setpoint writes permitted, speed ramp routed to the machine tender.

ObservationEdge-crack precursor at 1,412 mm drive side at 04:56:41. Nip t…

Edge-crack precursor at 1,412 mm drive side at 04:56:41. Nip trim of −40 kN/m in press-2 cleared it in 16 s without a break.

OutcomeRun complete in 11 m 42 s. 6.2 t off-spec, zero breaks, 6.1% l…

Run complete in 11 m 42 s. 6.2 t off-spec, zero breaks, 6.1% less dryer steam than the standing recipe. Reel R-24188 released with full genealogy.

Guardrails

An agent that can move a nip needs a leash

Pulpum writes to production equipment. Every capability is scoped, every write is policy-checked, and every action is written to an append-only audit log the mill owns.

  • Bounded action space. Each agent can only write to an explicit tag allow-list, inside per-tag rate and magnitude limits.
  • Policy engine before every write. Autonomy level, shift, grade, interlock state and operator presence are all evaluated before a setpoint moves.
  • Human-in-the-loop gates. Anything above the site threshold — speed ramps, grade releases, safety-adjacent moves — waits for a named approver.
  • Immutable audit log. Append-only, hash-chained, exportable, and retained on the mill's own storage.
  • Hard fallback. Loss of the edge node, the network or the model returns control to the DCS's last known-good state within one scan cycle.
  • Tenant and IP isolation. Furnish recipes, grade models and defect libraries never cross a customer boundary. On-prem deployment available.

Compliance posture

Compliance and certification status
StandardScopeStatus
SOC 2 Type IICloud control plane RUNNING In progress [ASPIRATIONAL]
ISO 27001Company-wide ISMS QUEUED Planned [ASPIRATIONAL]
IEC 62443Mill-edge OT security RUNNING Design-aligned
GDPROperator data SUCCEEDED Compliant
ISO 9001 / FSCQuality + chain of custody records SUCCEEDED Supported

Read the security overview

Autonomy

Four levels, set per agent and per tag

A mill does not go from manual to unattended in one step. Pulpum makes the level explicit, auditable and reversible at any time.

Autonomy levels and the human role at each
LevelWhat the agent doesWhat the human doesTypical time to reach
L1 · AdvisoryRecommends setpoints and explains whyEnters every change manuallyWeek 1
L2 · SupervisedProposes a write; it executes on approvalApproves each write in the HMIWeek 3–6
L3 · BoundedWrites inside tag, rate and magnitude limitsApproves ramps and grade releasesMonth 2–4
L4 · UnattendedRuns the envelope without promptingSets the envelope; reviews the shift recordMonth 6+ [ASPIRATIONAL]
Compliance

Certification status

We publish status honestly, including what is not done yet.

Certification status
FrameworkScopeStatusEvidence
SOC 2 Type IICloud control planeIn progress [ASPIRATIONAL]Report on request at completion
ISO 27001Company ISMSPlanned [ASPIRATIONAL]—
IEC 62443Mill-edge OT securityDesign-alignedArchitecture review pack
GDPROperator personal dataCompliantDPA + records of processing
ISO 9001 supportQuality recordsSupportedReel genealogy export
FSC chain of custodyFibre traceabilitySupportedGenealogy fields mapped
OT safety

Failing safe is a design requirement

The correct behaviour for a supervisory agent that loses confidence is to stop writing and hand back — quietly, immediately, and with a log entry.

Failure behaviour

  • Edge node loss → DCS holds last known-good state within one scan cycle
  • Network loss → edge continues within its envelope, buffers audit locally
  • Model confidence collapse → agent drops to advisory and raises an event
  • Sensor loss → dependent steps are blocked rather than run on stale data
  • Policy engine unreachable → all writes are refused, reads continue
  • Manual override → any operator action immediately supersedes the agent
Data

What leaves the mill, and when

The default is that very little does. You choose the rest explicitly.

  1. Stays local always

    Raw camera frames, full-rate DCS telemetry, operator identities and interlock state remain on the mill-edge node.

  2. Leaves only if enabled

    Frames of interest, labelled break events and aggregated run summaries — used for site-specific model training.

  3. Never shared across tenants

    Furnish recipes, grade models, defect libraries and any derived weights are isolated per customer, contractually and technically.

  1. You can export everything

    Run records, audit log, reel genealogy and model metadata export in JSON and CSV at any time, including on exit.

  2. You can delete everything

    Tenant deletion removes models, telemetry and derived artefacts within the contractual window, with written confirmation.

  3. Air-gapped option

    For sensitive producers, the mill edge runs disconnected with offline, signed model updates.

Multi-agent handoff

Agents negotiate, they do not collide

Two agents will want the same actuator. The orchestrator arbitrates on the run goal, not on who asked first — and the handoff is logged like any other step.

Contested move: press-2 nip load

  1. 01form_press.request(nip −0 kN/m) SUCCEEDED0.2 s

    Form-and-Press wants to hold nip load to protect post-press dryness.

  2. 02defect_inspect.request(nip −40 kN/m) SUCCEEDED0.2 s

    Defect-and-Inspect wants to reduce nip load to clear an edge-crack precursor.

  3. 03orchestrator.arbitrate SUCCEEDED0.4 s

    Break risk 0.62 outranks a 0.4-point dryness loss under the run goal "zero breaks". Defect-and-Inspect wins the actuator for 120 s.

  4. 04form_press.handoff(returned) SUCCEEDED120 s

    Actuator returned; Form-and-Press recovers dryness with vacuum instead. Post-press dryness lands at 47.1%.

Arbitration rules

  • Run goal first. Every request is scored against the declared goal, not the requesting agent's local objective.
  • Safety and breaks outrank quality. A break costs hours; a profile excursion costs minutes.
  • Time-boxed ownership. An agent holds a contested actuator for a bounded window, then must re-justify.
  • Everything is logged. The losing request, the score and the reason all appear in the run record.
  • Deadlocks escalate to a human rather than resolving by timeout.

See the agent roster

Enterprise

Standardise autonomy across the group

One policy model, one audit trail, one benchmark across every machine in every mill — with the grade and furnish models kept private to each site.

Talk to sales Enterprise details

  • SSO, SCIM and role-based access down to the tag level
  • Group-wide autonomy policy with per-site override and approval chains
  • Cross-mill benchmarking on broke, breaks, steam and first-pass quality
  • VPC, on-prem and fully air-gapped mill-edge deployment options
  • 99.5% control-plane SLA; edge autonomy survives control-plane loss
  • Dedicated deployment engineer and quarterly model review per site
FAQ

Straight answers

The questions mill managers and process engineers actually ask in the first meeting.

External penetration testing of the control plane and the mill-edge appliance is scheduled as part of the SOC 2 Type II programme [ASPIRATIONAL]. Results are shared with customers under NDA.

Get started

Get the security pack

Architecture diagrams, the OT threat model, the data-flow map and the policy-engine specification — sent under NDA.