Data handling
Every record accounted for,source to decision
GridAPM pilot workflows keep the ledger: where evidence came from, what AI assisted with, who reviewed the output, and which recommendations remain draft.
OT boundary
Site network
Workstation
GridAPM
Controlled OpenAI connection
Evidence in
AgenticGrid Pro Transformer APM
The other GridAPM product ProtectionAI Relay testing
Data lifecycle
Intake to return, one ledger
Four stages, each with an owner and a record — agreed before technical evaluation begins.
-
Intake
Approved evidence enters through agreed channels, keeping source, file identity, and provenance.
-
Local storage
Records live on the pilot workstation inside your perimeter — not on hosted infrastructure.
-
Review
AI output stays draft until a named engineer accepts, edits, or rejects it; every state change is logged.
-
Retention & return
At pilot end, evidence is returned or deleted to the agreed schedule; the decision record stays auditable.
Two sides of the ledger
What a pilot stores — and what we never see
What a pilot stores
- Pilot contact information
- Business contact details submitted through pilot, demo, newsletter, or email workflows.
- Website measurement metadata
- Consented analytics events, source page, referral or UTM data, CTA category, score band, and submitted business inquiry fields used for aggregate content analysis and relevant follow-up.
- Transformer evidence
- Approved diagnostic records, inspection notes, loading context, maintenance history, reports, photos, or exports used in a scoped pilot.
- Derived observations
- Reviewed fields, summaries, draft findings, evidence links, and recommendations created from approved source material.
- AI-assisted output
- Draft explanations, extraction suggestions, missing-evidence prompts, and report language that require human review before use.
What we never see
- Evidence outside the agreed scope
- Pilots use the minimum evidence needed for the agreed workflow — nothing else is collected.
- Confidential evidence in hosted services
- Confidential evidence is not sent to hosted services unless explicitly approved in the deployment profile.
- Customer evidence in analytics
- Public website analytics stay separate from tool answers, customer evidence, and confidential transformer data.
- Your live OT systems
- GridAPM reads approved exports. It never connects to protection, control, or SCADA systems.
Retention
Where each record lives — and when it leaves
Retention is a scoping decision, not a default. This table shows the standing posture; exact terms are agreed per pilot.
| Data category | Where it lives | Retained | At pilot end |
|---|---|---|---|
| Pilot contact information | Business contact systems | While the conversation is active | Deletable on request |
| Website analytics | Consent-gated analytics tooling | Aggregate, per the cookie policy | Never joined with pilot evidence |
| Transformer evidence | Pilot workstation, inside your perimeter | The agreed pilot term | Returned or deleted, per agreement |
| Derived observations & AI drafts | Pilot workstation | The agreed pilot term | Delivered in the evidence pack |
| Audit trail | Inside the evidence pack | With the decision record | Handed over at close-out |
Retention, deletion, export, and follow-up expectations are defined before pilot expansion — and pilot inquiry data is kept separate from customer evidence used in technical evaluation.
Pilot data boundaries
Commitments a pilot starts from
GridAPM favors local-first operation and conservative claims. Customer evidence remains inside approved project boundaries unless a deployment profile permits otherwise.
- Use the minimum evidence needed for the agreed pilot workflow
- Preserve source provenance, file identity, and reviewer context where practical
- Treat AI output as draft material until accepted, edited, or rejected by a reviewer
- Avoid sending confidential evidence to hosted services unless explicitly approved
- Keep public analytics separate from tool answers, customer evidence, and confidential transformer data
- Define retention, deletion, export, and follow-up expectations before pilot expansion
- Separate pilot inquiry data from customer evidence used in technical evaluation
Data handling FAQ
Questions data owners ask
Where does pilot evidence live?
On the pilot workstation inside your perimeter. GridAPM is local-first: evidence is processed where it is loaded, not on hosted infrastructure.
Does GridAPM send evidence to external AI providers?
Yes, when an operator requests an AI feature. GridAPM uses OpenAI only and sends the minimum approved context through the deployment's controlled outbound profile; deterministic calculations and the operational database remain local.
What happens to our data when the pilot ends?
Evidence is returned or deleted to the schedule agreed at scoping. The evidence pack — findings, reviewer identity, timestamps, decision state — is handed over as the pilot deliverable.
How is website data kept apart from pilot data?
Public analytics are consent-gated and aggregate, and they stay separate from tool answers, customer evidence, and confidential transformer data. Pilot inquiry details are likewise kept apart from technical evaluation evidence.
Start with the ledger
Agree scope, storage, review, and return before evaluation begins.