Docs
What protects the data, who can reach it, what the contract says about it, and an honest account of where mode40 stands on certification.
Data is encrypted in transit and at rest.
Data residency is set per customer at onboarding: AWS Canada Central in Montreal for Canadian data, US-East or US-West for US data, with no cross-border movement unless it is explicitly configured. Architecture and deployment has the full deployment picture and the site data path.
Identity runs on OAuth 2.0 with AWS Cognito as the identity provider. Cognito issues JWTs for the session, and it supports multi-factor authentication and password policies.
Tenant isolation is enforced by tenant ID together with IAM policy. One customer’s data is not reachable from another customer’s session.
Inside a tenant, access is granted by module, action, role, and site. Every one of them is enforced.
Agent actions are governed separately, by the Authority Matrix. Every agent carries an authority level per action type: observe, inform, suggest, act with approval, or act autonomously. Authority is checked before an agent acts, and a level that is not set defaults to suggest, so the fail-safe is the restrictive one. Authority can be conditioned, for example capped at a maximum value or scoped to named sites, and anything short of autonomous routes to a person through an approval workflow.
Audit logging is real, and it sits at the infrastructure level. AWS CloudTrail records activity across the account. AWS GuardDuty monitors continuously for unauthorized access. Both are operated by mode40.
Inside the platform, the Historian is a shipped module holding timestamped operational history, so the record of what happened on the floor is captured as it happens.
There is no customer-facing screen documented today that traces a given number back through its sources, so treat provenance questions as an implementation topic. The Trust Registry, which holds a verification record, is on the roadmap and is not available.
These are contract terms from the licensing agreement. The signed agreement governs.
Your data has the exit terms in full, the notice periods, and what the agreement leaves undefined.
The contractual availability term is 99.5%, measured monthly, excluding scheduled downtime and force majeure. That is the only availability number that exists, and it is the one to hold mode40 to.
Support hours, channels, severity levels, and response targets are set per engagement. No standard tiers are defined, so a customer who needs specific response times should get them written into the agreement rather than assume a published tier applies.
Also undefined today:
What is in place today:
What is not in place: mode40 holds no third-party security certifications. mode40 does not hold SOC 2 Type II. mode40 does not hold ISO/IEC 27001:2022. Neither audit is underway. Both are on the roadmap without a committed date, and the current status and plan are available on request.
PIPEDA sits in a different category. The licensing agreement commits mode40 to PIPEDA in its breach-notification clause. That is a stated compliance commitment, not a third-party attestation, and no certificate exists for it.
The Singularity runs on AWS, and AWS holds certifications covering the infrastructure AWS operates. Those certifications belong to AWS. mode40 does not inherit them, does not claim them, and does not offer them as an attestation of the Singularity. A certification of the platform would have to be earned by mode40, and it has not been.
We use cookies to understand how the site is used and to connect form submissions to earlier visits. No analytics or marketing cookies are set until you choose. Privacy Policy