Enterprise trust
Security, data handling and governance
This page states what is built today and what is scoped during deployment. Both are named plainly, because a vendor who is vague here is usually vague for a reason.
Deployment models
HSEPredict is designed to sit where your operational data already sits, rather than requiring it to move somewhere it should not go.
- Edge — processing at or near the site, for environments where telemetry should not leave the facility.
- Hybrid cloud — site-level collection with centralised intelligence and portfolio reporting.
- Industrial private cloud — deployment within your own tenancy.
- On-premise — fully within your infrastructure, for environments where that is a regulatory requirement.
Which model applies is determined during discovery, against your OT security posture and data residency requirements.
Data handling
The platform consumes operational and safety signals from approved sources only — telemetry, asset systems, incident records, inspection findings and human reports. Sources are connected explicitly during integration; nothing is collected by default.
Retention periods, data residency and deletion procedures are agreed before integration rather than assumed. Where your operations span jurisdictions with different requirements, that is established during discovery.
Access control
Access is role-based, and the roles reflect operational reality: an HSE operations centre, a site supervisor, a field worker, an executive and a regulator see different things from the same underlying intelligence.
Enterprise workspaces isolate data between organisational units. Audit trails record who accessed what and when, which matters both for internal governance and for anything that later becomes a regulatory question.
Worker privacy and the governance commitment
Predictive output is not used in individual performance management. This is stated in the product report, on the methodology page, and here, because it is the commitment most likely to be tested.
The reason is practical as well as ethical. If frontline personnel come to believe that reporting a near miss increases scrutiny of their own team, reporting rates decline and the data degrades. A predictive safety system can undermine its own inputs. Where worker monitoring is involved — computer vision on site cameras, movement data, access events — the scope, purpose and consultation requirements are agreed with you and, where appropriate, with worker representatives before deployment.
What is a deployment activity
Security hardening, governance configuration, penetration testing and formal certification are deployment activities, scoped during discovery. They are not represented here as completed work.
HSEPredict does not currently hold third-party security certifications. If your procurement process requires them, say so early and we will tell you honestly what the timeline looks like rather than discovering it late in an evaluation.