Security & compliance

Your data, your control.

SemenStrawCOUNTER is built edge-first: AI inference, image storage, and counting all happen on the unit in your facility. Cloud features are opt-in and transmit only structured count records — never images.

Edge-first by default

All AI inference and image storage happen on the local edge unit. No images leave your facility unless you explicitly enable cloud sync.

Encryption everywhere

AES-256 at rest, TLS 1.3 in transit. Edge disks are full-disk encrypted; backups are encrypted with customer-managed keys when required.

SSO, RBAC, MFA

Integrate with Okta, Entra ID, Google, or any SAML/OIDC IdP. Granular roles for operators, supervisors, auditors, and admins. MFA enforceable per role.

Tamper-evident audit log

Every scan, override, login, and configuration change is appended to an immutable, signed audit log — exportable for your auditors.

Data residency

Choose where (and whether) data is replicated. Default deployments support EU, US, and APAC regions; air-gapped sites are fully supported.

Secure update pipeline

Firmware and AI model bundles are signed, atomic, and rollback-safe. No silent updates — operators approve every deployment.

Compliance

Standards we map to.

GDPR

Data minimization, DPA on request, EU data residency option.

ISO 27001

Controls aligned across access, change, supplier, and incident management.

SOC 2 (in progress)

Type II audit underway; evidence available under NDA.

HIPAA-aware

While not health data per se, controls map to HIPAA where required for veterinary or research customers.

Need our security questionnaire?

We'll send our SIG/CAIQ responses, architecture diagram, and DPA under NDA.

Request security pack