Security & governance

Engineering governance, security and AI traceability

Who can see a project, who can rule on a finding, and what was decided by whom. An AI governance platform for engineering work has to answer all three, and record the answer as it happens.

Access control

Three roles, scoped to the organisation or the project

Access is granted at the level the work happens. Engineering access control is inherited from your directory rather than maintained separately.

ORGANISATION

Organisation admin

Owns the tenant. Manages workspaces, invites members and sets who administers what.

  • Create and manage workspaces
  • Manage organisation membership
WORKSPACE

Workspace admin

Owns the standards library and the projects inside a workspace, and who may work in them.

  • Maintain the standards library
  • Create projects and assign members
PROJECT

Member

Works on the projects they are assigned to. Reviews findings and records dispositions.

  • Run assurance on assigned projects
  • Accept, reject or override findings

Sign-in runs through Microsoft Entra ID, so joiners, movers and leavers are handled by the directory you already govern.

Engineering audit trail

Every action is written as it happens

Engineering traceability is not a report you generate at the end. The record of who did what, when and on what basis is produced by the work itself, so it already exists when a customer, inspector or auditor asks.

ACTION LOG · WHAT IS CAPTURED
WHOIdentity and roleResolved from the directory at sign-inEVERY ACTION
WHATThe action takenAccept, reject, override, commentEVERY ACTION
WHYThe justification givenRequired on an overrideON OVERRIDE
AGAINSTThe clause and source quoteCarried with the findingEVERY FINDING

AI traceability

The system shows its working, and never rules on anything

Governance of AI output is not a policy statement here. It is built into what a finding contains and what it is allowed to do.

EVIDENCE

Nothing is asserted

A finding carries the clause it was checked against and the quote it came from, so it can be verified against the source rather than trusted.

CONFIDENCE

Reported separately from the verdict

How certain the system is sits beside the verdict rather than inside it, so a reviewer can weigh both independently.

PRECEDENCE

The governing order is yours to set

Which standard takes precedence on a project is configured, not inferred, and the decision is visible on every finding it shaped.

standrdX does not make engineering decisions and does not replace engineering judgment. No finding takes effect until an engineer approves it, and the approval is attributed.

Platform

The controls in place

Access, identity, logging and evidence, listed individually rather than described as a single block.

REQUEST THE SECURITY PACK →
Role-based accessLIVE
Microsoft Entra sign-inLIVE
Action & decision loggingLIVE
Evidence on every findingLIVE
Export historyRETAINED
Precedence set per projectCONFIGURED

FAQ

Questions from security and procurement

How is our engineering data handled?

Your standards, specifications and deliverables are processed to produce findings for your own project. Data handling, retention and any use of customer material are set out in the security pack and in your contract, and we answer them in writing rather than on a web page.

Who can see a project?

Only the members assigned to it. Workspace admins control project membership, and organisation admins control who administers each workspace.

Can a reviewer overrule the system?

Yes, and the override requires a justification. Both the original verdict and the override are kept, with the reviewer attributed.

How do we prove a decision to an auditor?

The finding carries the clause it was checked against and the quote it came from, and the action log carries who ruled on it, when and on what basis.

Do you support SAML or other identity providers?

Microsoft Entra ID is the supported sign-in method today. Other providers are not connected.

Which certifications do you hold?

Certification status is confirmed directly as part of a security review rather than claimed here. Ask for the security pack and we will answer it in writing.

Next step

Bring it to your security review.

We will answer a security questionnaire in writing and walk your IT and procurement teams through access, logging and data handling.