Your recipes are the asset. We treat them that way.

Anodela is designed for the approval bar of IT, OT, quality and EHS in an industry where a single leaked coating recipe or an unlogged setpoint change is unacceptable.

Reviewed by the security teams of global cell makers [PLACEHOLDER]

Northvolt-class OEMVolta CellsAmperex ESSHelion MotorsKestrel EnergyAnode WorksPrisma CellsSilica PowerTerra Grid StorageMeridian EVCathode LabsAurora Gigafactory

Controls in every deployment

Encryption everywhere

TLS 1.3 in transit, AES-256 at rest, per-tenant keys with optional customer-managed keys.

Identity & access

SSO/SAML, OIDC, SCIM provisioning and RBAC scoped to plant, line and agent.

Tenant isolation

Per-tenant data stores, vector indexes and model scoping — no cross-tenant retrieval, ever.

Immutable audit

Append-only records of every perception, proposal, approval, execution and rollback.

Data residency

EU, US, Korea, Japan and China-domestic regions, plus on-prem and air-gapped modes.

Secure edge

Signed images, measured boot, mTLS between edge and control plane, and OTA with rollback.

Chemistry IP never has to leave the plant

Coating recipes, formation protocols and tolerance windows are the crown jewels of a cell maker. Anodela's architecture assumes they must never be pooled.

On-prem and air-gapped deployment

The full control path — perception, reasoning, control and audit — runs on your hardware. Updates arrive as signed bundles you inspect and approve.

  • Zero egress mode with no outbound connections required
  • Signed, reproducible model and runtime bundles
  • Local audit storage with your retention policy

Federated learning, not data pooling

Fleet improvements are shared as model updates and rare-failure priors under terms you approve — never as raw recipes, images or cell records.

  • Opt-in per model family and per data class
  • Differential controls on anything derived from customer data
  • Contractual and technical prohibition on cross-tenant retrieval

Evidence for qualification, not just compliance

The audit trail is designed to strengthen your IATF 16949 and IEC 62660 evidence: every autonomous action is traceable to the cell it affected.

  • Action-to-cell-genealogy linkage for every executed change
  • Exportable evidence packs for audits and customer PPAP
  • Named approver and timestamp on every envelope change

Certifications and standards

Certification status is tracked transparently. Items marked in progress are not yet awarded.

ProgrammeStatusNotes
SOC 2 Type IIIn progress [ASPIRATIONAL]Type I complete; Type II observation window under way
ISO 27001Planned [ASPIRATIONAL]Targeted after SOC 2 Type II
GDPRAlignedDPA available; minimal personal data processed
IATF 16949 / ISO 9001Supports customer complianceAnodela produces evidence; certification is the plant's
IEC 62660 / UN38.3 / ULSupports customer complianceTraceability and genealogy evidence for cell safety programmes
Penetration testingAnnual + on major releaseThird-party; summary letter available under NDA

Autonomy with a stop condition

Fail-safe by default

Coating, weld, robot and AGV actions degrade to a safe stop on loss of confidence or connectivity.

Simulation gate

No control envelope is armed until the twin validates it against as-built line behaviour.

Human-in-the-loop

Safety-relevant and high-impact decisions always require a named approver.

Reversibility

Every executed change is idempotent and reversible, with automatic rollback on adverse signal.

How a security review usually runs

  1. Pack

    You receive the security pack, architecture diagrams, DPA and pen-test summary under NDA.

  2. Workshop

    A joint session with your IT, OT and quality teams covering isolation, egress and audit.

  3. Deployment design

    Regional, on-prem or air-gapped mode selected and documented.

  4. Sign-off

    Controls mapped to your internal standard; approvals recorded before connectors go live.

The numbers we hold ourselves to

0Cross-tenant data incidents [PLACEHOLDER]
7 yrDefault audit retention
100%Actions covered by the audit trail
24/7Security escalation

What security and quality teams say

“We were stranded at 63% first-pass yield for five months. Anodela ran in shadow for six weeks, then took bounded control of coat weight and drying. We crossed 91% in the next quarter.”
Marta VogelPlant Director, Volta Cells
“It reads our CT and vision streams the way a great process engineer does — except it does it on every metre of web, on every shift, and it writes the correction back before the defect becomes scrap.”
Daniel OkaforHead of Process Engineering, Amperex ESS
“The audit trail was what got quality to yes. Every proposal, approval and executed setpoint is linked to cell genealogy, so our IATF evidence got stronger, not weaker.”
Sung-Ho ParkQuality Director, Prisma Cells

Built for the world's largest gigafactories

Multi-site programs

Standardize coating, weld and formation autonomy across every plant with central model governance and per-site envelopes.

Factory edge fleet

Managed Jetson/IGX clusters with OTA updates, versioned rollbacks and 99.9% availability targets.

Dedicated assurance

Named process-AI engineer, qualification support, PPAP-aligned documentation and 24/7 escalation.

Outcome-based commercials

Multi-year agreements with pricing tied to first-pass yield, scrap and formation cost.

Security questions

Not without explicit, per-model-family opt-in. By default your data trains only your models, inside your tenant.

Very little — operator and engineer identity for approvals and audit. No biometric or productivity monitoring is performed.

Yes, customer-managed keys are supported for cloud deployments, and in on-prem mode key material never leaves your infrastructure.

Coordinated disclosure with a published contact, severity-based remediation targets, and signed OTA updates that can be staged and rolled back per line.

Send us your security questionnaire.

Most reviews complete in two weeks. We answer in your format, not ours.