Security & deployment
The workbench staysinside your boundary
GridAPM runs as a local-first workbench on an engineer workstation. Approved evidence comes in through agreed channels. There is no autonomous OT connection or unreviewed action; OpenAI-powered requests use a controlled outbound boundary.
OT boundary
Site network
Workstation
GridAPM
Controlled OpenAI connection
Evidence in
AgenticGrid Pro Transformer APM
The other GridAPM product ProtectionAI Relay testing
Deployment model
Local-first by design
Three deployment facts define the security review before any control checklist does.
- Local-first workstation
- The workbench installs on an engineer workstation inside your perimeter. Core evidence processing remains local, with no new application server to stand up. OpenAI access is governed separately.
- Controlled OpenAI egress
- AI features use OpenAI only and send the minimum approved context for a requested operation. Telemetry remains off; your security team reviews the credential, proxy, retention, and data policy.
- No OT connection
- GridAPM reads approved evidence files and exports. It never connects to protection, control, or SCADA systems — there is no path from the workbench to your operational network.
Security controls
The controls a pilot runs under
Seven controls scope what data is approved, what AI may assist with, who reviews output, and which decisions remain outside the software boundary.
- Local-first pilot path
- Pilots start from approved datasets and local review workflows, with OpenAI access scoped and approved before broader deployment.
- Engineer approval
- AI-assisted recommendations remain draft material until a responsible engineer reviews, edits, approves, rejects, or escalates them.
- Evidence traceability
- Material findings preserve source evidence, assumptions, policy context, reviewer state, and audit history.
- No autonomous control
- GridAPM performs no autonomous transformer protection, switching, or control, and holds no final operational authority.
- Deployment boundaries
- OpenAI is the sole AI provider. Its outbound access is enabled only through an approved deployment profile; product telemetry remains off.
- Telemetry redaction
- If RUM, error monitoring, or session replay is ever enabled, it redacts query strings, form values, request and response bodies, headers, cookies, local variables, tool inputs, customer evidence, sensitive URLs, and screenshots unless separately disclosed and consented.
- Utility OT respect
- Pilot scope respects utility security reviews, operational technology segmentation, sensitive data boundaries, and procurement controls.
Pilot definition
What security and engineering teams define first
Security review is strongest when the pilot starts narrow: approved evidence, known reviewers, local workbench expectations, and clear deployment boundaries.
- Approved transformer population and evidence scope
- Local evidence files, source provenance, and review owners
- Defined AI advisory boundaries and human approval gates
- Pilot-specific data handling, retention, and export expectations
- Security review before enterprise integrations or hosted services
- Clear separation between draft recommendations and approved actions
Standards context
Framed by NIST AI RMF
NIST AI RMF 1.0
National Institute of Standards and Technology
Risk framing for AI systems: govern, map, measure, manage.
GridAPM's AI risk framing follows the NIST AI Risk Management Framework: bounded agent tasks, visible evidence, human approval, audit trails. Deployment reviews plug into your existing OT cyber-security program — they do not replace it.
GridAPM works within the context of these documents. Context is not certification.
Security FAQ
Questions security reviewers ask first
Where does GridAPM run?
On an engineer workstation inside your perimeter. The pilot workbench keeps operational records and deterministic processing local; requested OpenAI assistance uses approved outbound access.
Does anything leave our network?
OpenAI is the sole AI provider and requires an approved outbound profile. Product telemetry stays off, and the credential, proxy, retention, and evidence boundary are agreed in security review.
Does GridAPM connect to our OT systems?
No. GridAPM reads approved evidence exports. It never connects to protection, control, or SCADA systems, and it holds no operational authority.
How does a security review start?
With the pilot definition: approved evidence scope, named reviewers, data handling and retention expectations, and deployment boundaries — documented before technical evaluation begins.
Put the boundary in writing
Scope a controlled pilot with your security team — approved evidence, named reviewers, documented boundaries.