muono
ReferenceSecurity specification
Revision AStatus Current

Security & deployment specification

For your IT and OT reviewers
Purpose

Answerable to your OT team, not only your IT team.

This page is written to be read by the person whose signature a pilot needs. It states where Muono runs, what it reaches, what it records, and which certifications we hold today, which is none of them yet. Where a claim is not settled, the clause says so rather than implying otherwise.

Deployment

Four models, and your security review picks one: your own cloud tenancy on Azure or AWS, Muono-hosted, fully on-premise, or hybrid with an edge collector on site and the model in the cloud. The matrix below reads down each column.

Read the clause
Agreed before connection

Control-system access

Access posture is set per connector and agreed at deployment rather than asserted here. Historians and business systems are read on a schedule you set. Where a connector would reach further than reading, it is scoped, written down and signed before it is enabled.

Read the clause
Per connector in writing

Data residency

The region is fixed at deployment and does not move afterwards. GDPR obligations are supported in every deployment model, including subject access and deletion. On-premise and hybrid keep the raw side inside your own perimeter.

Read the clause
Fixed at deployment

Identity and authority

Your existing directory, with roles mapped to the authority levels an agent may act under. Irreversible actions hand off to a named approver rather than to a queue, and the level an agent runs at is a decision your team makes deliberately.

See agentic automation

Audit

Every agent action is recorded against the person who authorised it, with the readings and documents it relied on. Runs are replayable after the fact and their side-effects reversible. Model state is viewable at any past date, so a submission can be reconstructed as it stood.

Read the clause
Attributable and replayable

Certification

SOC 2, ISO 27001 and IEC 62443 alignment are in progress. We are not certified against them today and will not claim otherwise, including by implication. When that changes this clause changes with it, and the revision above will say so.

Read the clause
In progress not held
Table

Find the column your organisation would accept, and read down it.

Your cloud
Muono
On
Hybrid
Where data sits
Your tenancy
Muono tenancy, your region
Your data centre
Raw on site, model copy in cloud
Where it runs
Your subscription
Muono
Your hardware
Split, collector on site
Control systems
Set per connector
Set per connector
Set per connector
Collector only
Residency control
Yours
Region fixed at signing
Absolute
Yours, on the raw side
Suits
A standing cloud policy
Fastest pilot start
Data that cannot leave site
Thin site links

Queries

Can our OT team review this before any commercial conversation?
Yes, and it is often the right order. The access questions are cheaper to answer before a pilot is scoped than after one has been agreed.
Why does the control-system clause not simply say read-only?
Because the honest answer is per connector, agreed at deployment. Writing "read-only, always" here would be a claim we would then have to qualify in the room, which is worse than stating the position plainly.
You have no certifications. Why should we proceed?
Judge the architecture, the deployment model and the audit trail, which are the things a certificate attests to anyway. If your policy requires a certificate before a pilot, say so now and we will tell you plainly that we cannot meet it yet.
Can a pilot run entirely inside our perimeter?
Yes, the on-premise column. The hybrid column exists for sites where raw data must stay put but the model may sit in a cloud tenancy you control.

Send this page to your OT reviewer.

If a clause does not clear your policy, that is worth knowing before a pilot is scoped rather than after.