SECURITY & ARCHITECTURE

Designed to fit industrial environments without becoming part of the control loop.

RootTruth™ is being developed as a local-first investigation platform that observes and preserves evidence from existing automation systems. This page summarises the intended security and deployment principles for customer discovery and pilot discussions.

CORE PRINCIPLES

A clear boundary between investigation and machine control.

01

Local-first deployment

Core event capture, evidence storage and investigation are intended to operate on customer-controlled infrastructure without a permanent internet dependency.

02

Observe, don’t command

The standard RootTruth™ evidence workflow is intended to read and record relevant machine information, not issue automatic PLC output commands or become a safety/control function.

03

Least-access mindset

Deployment should use only the connectivity and permissions required for the agreed evidence scope, subject to the customer’s IT/OT standards.

04

Customer-controlled data

Retention, storage location, user access and any future cloud-enabled functions should be agreed with the customer rather than silently imposed by the product.

DATA PATH

Industrial evidence in. Investigation workflow out.

PLC / CONTROLOPC UASelected tags, states and event triggers
VIDEORTSP / ONVIFApproved IP camera streams
→
RootTruthCapture · Synchronize · StoreRolling buffers, event evidence, cases and investigation history
→
AUTHORIZED USERSWindows client
OPTIONAL / FUTUREApproved APIs or cloud services

Exact protocols, ports, storage requirements and supported combinations will be confirmed in release documentation and during site discovery before production deployment.

ACCESS MODEL

Named access with engineering roles.

The MVP direction uses named user accounts and role-based permissions appropriate to an investigation platform. Event configuration is treated separately from ordinary investigation access.

AdministratorSystem-level configuration and user administration.
Engineering ManagerInvestigation oversight, cases, actions and reliability workflow.
EngineerDay-to-day investigation and case work.
ViewerRead-oriented access where appropriate.
Event configuration permissionSeparate control over who may change event definitions.

DEPLOYMENT REVIEW

Security is part of site discovery, not an afterthought.

Network placement

Agree where the RootTruth™ server or VM sits, which OT assets it may reach, and which routes are permitted.

Identity & access

Confirm users, roles, account lifecycle expectations and any future SSO requirements.

Storage & retention

Size evidence retention around event volume, video load, customer policy and available storage.

Backup & recovery

Agree what evidence/configuration requires backup and how recovery responsibilities are divided.

Patch & maintenance

Define how application updates, Windows/server maintenance and dependency updates are handled.

Logging & auditability

Confirm the required audit trail and operational logs against the final release capabilities.

CURRENT PRODUCT STATUS

Security claims will be verified against the shipping build.

RootTruth™ is still in development. YellowCore will not present planned controls as certified or fully implemented until they have been validated in the release build and supporting documentation.

No certification claims yetNo ISO 27001, SOC 2 or similar certification is claimed by this page.
No hidden cloud dependencyThe core product direction remains local-first; optional online services should be separately disclosed.
Release-specific documentationPorts, dependencies, encryption details, backup guidance and hardening requirements will be published once technically verified.

SHARED RESPONSIBILITY

RootTruth security depends on both product controls and the customer environment.

YELLOWCORE

Product

Secure software design, release documentation, supported configuration, vulnerability handling and product updates.

CUSTOMER

Environment

Network segmentation, operating-system policy, identity governance, backups, physical access and infrastructure security.

TOGETHER

Deployment

Agree connectivity, evidence scope, retention, access, responsibilities and validation before production activation.

IT / OT REVIEW

Have a security or architecture requirement?

Bring your IT/OT standards into the pilot discussion early so the deployment can be shaped around them.