Security & process IP

Your recipes are the company. We treat them that way.

A packaging fab’s process IP is its entire competitive position. Chipira is architected so that protecting it is a property of the system, not a promise in a contract.

Request the security pack

The default

Nothing leaves the building

Chipira runs its perception and control models on fab-edge hardware inside your fab. Inference happens there. Telemetry is stored there. Your defect corpus, your recipes and your fine-tuned models live in your tenant, scoped by construction rather than by policy.

The control plane governs models and fleets — it does not need your process data to do that job, so it does not receive it. Where an organisation wants even that governance on site, the control plane can be deployed in your private VPC or entirely on your premises.

Cross-fab learning — the mechanism by which a rare defect pattern learned in one fab could help another — exists, and it is genuinely valuable. It is also strictly opt-in and contractual. It is never a default, never a condition of using the product, and never a side effect of an upgrade.

Enterprise deployment options

Controls

What is actually implemented

Identity and access

SSO with your identity provider, role-based access control down to the agent and envelope level, and separation between who may view, who may approve and who may widen an envelope.

Encryption

Encryption in transit and at rest across the edge, control plane and data stores, with key management appropriate to on-premise and air-gapped deployments.

Tenancy

Per-tenant data, vector store, memory and model scoping. Retrieval is permission-aware. There is no shared index across customers.

Audit

An immutable, tamper-evident record of every perception, proposal, approval, write-back, exception and rollback — attributable to an agent, a model version and a person.

Action envelopes

Versioned bounds on every tool interaction, owned and approved by your process engineers. Widening one is itself an audited, approved action.

Fail-safe behaviour

Fail-safe tool stop and robotic handling, idempotent steps, automatic rollback on envelope breach, and graceful degradation to your existing control on any Chipira failure.

Programme

Compliance posture, stated plainly

We would rather tell you where we are than imply where we are not.

SOC 2 Type I
In progress [ASPIRATIONAL]. Available for review with prospective design partners under NDA as the programme matures.
SOC 2 Type II
Planned following Type I [ASPIRATIONAL]. Target timing is discussed openly during enterprise scoping.
Penetration testing
Third-party testing planned ahead of general availability, with summary reports available under NDA [ASPIRATIONAL].
Standards alignment
Aligned to warpage, void and defect classification standards and package-reliability practices relevant to your qualification flow.
Data processing
Documented data-flow diagrams, processing purposes and retention controls, with customer-configurable retention in on-premise deployments.
Sub-processors
A maintained sub-processor list, with material changes notified in advance. Air-gapped deployments have none.

Where data sits

Three tiers, three trust boundaries

The boundary that matters is the one at the edge of your building. Everything above it is governance; everything below it is your line.

Three-tier architecture diagram showing the cloud or private-VPC control plane, the fab-edge tier and the line tier of production tools.
The control plane governs models and fleets. Process data and inference stay at the fab edge. Chipira architecture illustration.

Trust model

How autonomy is granted and withdrawn

  1. Grounding before generation

    Retrieval over your recipes, specs, design rules and standards, with enforced citations. Outputs that cannot cite a source are rejected before they reach a decision.

  2. Human-in-the-loop by default

    High-impact and yield-critical decisions require explicit approval until measured accuracy has earned a higher autonomy gate.

  3. Continuous evaluation

    Golden-dataset and LLM-as-judge evaluation gates every model and prompt change in CI. A regression blocks the release.

  4. Automatic revocation

    Rolling accuracy is monitored against each gate’s floor. Drift below the floor withdraws autonomy automatically and escalates — it does not wait for a quarterly review.

The question is not whether your model is good. It is whether I can prove to an auditor what it did last Tuesday.

Quality and compliance leadAutomotive-grade packaging

Composite drawn from design-partner and industry conversations. Illustrative, not a customer endorsement.

Audit

One line, fully attributable

Every audit record carries the agent, the model version, the grounding sources, the twin verdict, the envelope it was checked against, the human who approved it, and the verified outcome. It is designed to be read by a change-control board.

Audit schema reference

audit/2026-07-27T10:41:07Z.json
{
  "ts": "2026-07-27T10:41:07.412Z",
  "agent": "warpage_defect",
  "model": "void-xray-ct@4.2.1",
  "tenant": "fab-kh-04",
  "subject": { "package": "PKG-4471-A", "step": "post-reflow-xray" },
  "finding": {
    "class": "void", "site": "bump C7", "confidence": 0.994
  },
  "grounding": [
    "spec/pkg-4471/rev-C#4.2",
    "standard/void-classification#class-2"
  ],
  "twin": { "verdict": "out_of_spec", "predicted_yield_delta": -0.031 },
  "envelope": "inspect-line4@7",
  "action": { "type": "route", "to": "rework", "autonomy": "L2" },
  "approval": { "mode": "escalated", "by": "k.tanaka" },
  "verified": { "by": "ct-rescan", "result": "confirmed" },
  "immutable": true
}

Illustrative audit record.

Operational security

How we run ourselves

Least privilege, including us

Chipira personnel have no standing access to customer tenants. Support access is time-bound, purpose-bound, customer-approved and logged into the same audit trail your engineers read.

Signed, staged releases

Edge artifacts are signed and delivered through governed release channels with staged rollout and per-site pinning. Nothing auto-updates on a production line.

Secure development

Dependency and secret scanning, infrastructure as code, reviewed changes, and evaluation gates that treat a model regression as a build failure.

Incident response

A documented response process with customer notification commitments, and a post-incident report that includes what the audit trail shows.

Security questions

What reviewers ask

  • No. Frontier models are used for reasoning and question answering behind a router; your process data is not used to train third-party foundation models. Fine-tuning happens on models scoped to your tenant.

  • Not by default. There is no standing access to customer tenants. Any support access is requested, time-bound, approved by you and written into the same immutable audit trail.

  • Documented export of your telemetry, labelled corpus and audit trail, and defined handling of tenant-scoped model artifacts on termination. Ask for the exit terms during the first commercial conversation, not the last.

  • Yes, and some lines should insist on it. You trade automatic fleet updates and any cross-site learning for a deployment with no outbound connectivity and offline signed model delivery.

Due diligence

Ask us the hard questions first.

We would rather fail your security review early than pass it by omission. Request the architecture and security pack and put it in front of your IT/OT and IP teams before we talk commercials.