Product
Secure software design, release documentation, supported configuration, vulnerability handling and product updates.
SECURITY & ARCHITECTURE
RootTruth™ is being developed as a local-first investigation platform that observes and preserves evidence from existing automation systems. This page summarises the intended security and deployment principles for customer discovery and pilot discussions.
CORE PRINCIPLES
Core event capture, evidence storage and investigation are intended to operate on customer-controlled infrastructure without a permanent internet dependency.
The standard RootTruth™ evidence workflow is intended to read and record relevant machine information, not issue automatic PLC output commands or become a safety/control function.
Deployment should use only the connectivity and permissions required for the agreed evidence scope, subject to the customer’s IT/OT standards.
Retention, storage location, user access and any future cloud-enabled functions should be agreed with the customer rather than silently imposed by the product.
DATA PATH
Exact protocols, ports, storage requirements and supported combinations will be confirmed in release documentation and during site discovery before production deployment.
ACCESS MODEL
The MVP direction uses named user accounts and role-based permissions appropriate to an investigation platform. Event configuration is treated separately from ordinary investigation access.
DEPLOYMENT REVIEW
Agree where the RootTruth™ server or VM sits, which OT assets it may reach, and which routes are permitted.
Confirm users, roles, account lifecycle expectations and any future SSO requirements.
Size evidence retention around event volume, video load, customer policy and available storage.
Agree what evidence/configuration requires backup and how recovery responsibilities are divided.
Define how application updates, Windows/server maintenance and dependency updates are handled.
Confirm the required audit trail and operational logs against the final release capabilities.
CURRENT PRODUCT STATUS
RootTruth™ is still in development. YellowCore will not present planned controls as certified or fully implemented until they have been validated in the release build and supporting documentation.
SHARED RESPONSIBILITY
Secure software design, release documentation, supported configuration, vulnerability handling and product updates.
Network segmentation, operating-system policy, identity governance, backups, physical access and infrastructure security.
Agree connectivity, evidence scope, retention, access, responsibilities and validation before production activation.
IT / OT REVIEW
Bring your IT/OT standards into the pilot discussion early so the deployment can be shaped around them.