Data handling

Every record accounted for,source to decision

GridAPM pilot workflows keep the ledger: where evidence came from, what AI assisted with, who reviewed the output, and which recommendations remain draft.

OT boundary

Site network

Workstation

GridAPM

Controlled OpenAI connection

Evidence in

Operational records and deterministic processing stay local. Requested OpenAI assistance sends only the approved bounded context needed for that operation through the controlled outbound connection.

AgenticGrid Pro Transformer APM

The other GridAPM product ProtectionAI Relay testing

Compare both products

Data lifecycle

Intake to return, one ledger

Four stages, each with an owner and a record — agreed before technical evaluation begins.

  1. Intake

    Approved evidence enters through agreed channels, keeping source, file identity, and provenance.

  2. Local storage

    Records live on the pilot workstation inside your perimeter — not on hosted infrastructure.

  3. Review

    AI output stays draft until a named engineer accepts, edits, or rejects it; every state change is logged.

  4. Retention & return

    At pilot end, evidence is returned or deleted to the agreed schedule; the decision record stays auditable.

Two sides of the ledger

What a pilot stores — and what we never see

What a pilot stores

Pilot contact information
Business contact details submitted through pilot, demo, newsletter, or email workflows.
Website measurement metadata
Consented analytics events, source page, referral or UTM data, CTA category, score band, and submitted business inquiry fields used for aggregate content analysis and relevant follow-up.
Transformer evidence
Approved diagnostic records, inspection notes, loading context, maintenance history, reports, photos, or exports used in a scoped pilot.
Derived observations
Reviewed fields, summaries, draft findings, evidence links, and recommendations created from approved source material.
AI-assisted output
Draft explanations, extraction suggestions, missing-evidence prompts, and report language that require human review before use.

What we never see

Evidence outside the agreed scope
Pilots use the minimum evidence needed for the agreed workflow — nothing else is collected.
Confidential evidence in hosted services
Confidential evidence is not sent to hosted services unless explicitly approved in the deployment profile.
Customer evidence in analytics
Public website analytics stay separate from tool answers, customer evidence, and confidential transformer data.
Your live OT systems
GridAPM reads approved exports. It never connects to protection, control, or SCADA systems.

Retention

Where each record lives — and when it leaves

Retention is a scoping decision, not a default. This table shows the standing posture; exact terms are agreed per pilot.

Retention and return posture by data category
Data category Where it lives Retained At pilot end
Pilot contact information Business contact systems While the conversation is active Deletable on request
Website analytics Consent-gated analytics tooling Aggregate, per the cookie policy Never joined with pilot evidence
Transformer evidence Pilot workstation, inside your perimeter The agreed pilot term Returned or deleted, per agreement
Derived observations & AI drafts Pilot workstation The agreed pilot term Delivered in the evidence pack
Audit trail Inside the evidence pack With the decision record Handed over at close-out

Retention, deletion, export, and follow-up expectations are defined before pilot expansion — and pilot inquiry data is kept separate from customer evidence used in technical evaluation.

Pilot data boundaries

Commitments a pilot starts from

GridAPM favors local-first operation and conservative claims. Customer evidence remains inside approved project boundaries unless a deployment profile permits otherwise.

  • Use the minimum evidence needed for the agreed pilot workflow
  • Preserve source provenance, file identity, and reviewer context where practical
  • Treat AI output as draft material until accepted, edited, or rejected by a reviewer
  • Avoid sending confidential evidence to hosted services unless explicitly approved
  • Keep public analytics separate from tool answers, customer evidence, and confidential transformer data
  • Define retention, deletion, export, and follow-up expectations before pilot expansion
  • Separate pilot inquiry data from customer evidence used in technical evaluation

Data handling FAQ

Questions data owners ask

Where does pilot evidence live?

On the pilot workstation inside your perimeter. GridAPM is local-first: evidence is processed where it is loaded, not on hosted infrastructure.

Does GridAPM send evidence to external AI providers?

Yes, when an operator requests an AI feature. GridAPM uses OpenAI only and sends the minimum approved context through the deployment's controlled outbound profile; deterministic calculations and the operational database remain local.

What happens to our data when the pilot ends?

Evidence is returned or deleted to the schedule agreed at scoping. The evidence pack — findings, reviewer identity, timestamps, decision state — is handed over as the pilot deliverable.

How is website data kept apart from pilot data?

Public analytics are consent-gated and aggregate, and they stay separate from tool answers, customer evidence, and confidential transformer data. Pilot inquiry details are likewise kept apart from technical evaluation evidence.

Start with the ledger

Agree scope, storage, review, and return before evaluation begins.

Type to search research, platform pages, and tools.