NADIR / Company / 03 of 04
Where your data sits, and for how long.
A monitoring layer sees a great deal about how a fleet operates. The defensible position is to hold as little of it as possible, keep what remains inside your own tenancy, and make every access — including ours — a matter of record.
Posture
Read-only is a security property, not just a safety one.
The absence of an ECU write path removes an entire category of risk before it can be mitigated. There is no credential that grants vehicle write access, because there is no code path it could authorise. A compromise of NADIR is a confidentiality incident, not a fleet-safety incident, and that distinction is worth more than any control we could add on top of an actuating design.
The same reasoning applies to the edge. Fleets whose data may not leave their network run the Pulse pack on-premise; scoring happens inside their perimeter and only derived tiers and evidence digests cross the boundary.
Retention
Keep the least of what is most sensitive.
Raw telemetry — the position traces and CAN frames that describe how your drivers actually drive — is the most sensitive artefact in the system and the shortest-lived. It is dropped at thirty days. Derived residuals and tier history persist for thirteen months in your tenancy. Evidence bundles and the access log are customer-held for seven years.
Model weights are the only thing we hold, and they are pinned rather than mutable, so a bundle signed today can be reproduced against the exact weights that produced it.
Verification
You should not have to take our word for it.
Every evidence bundle verifies offline against its own signature, with no call to our infrastructure and no credentials. That property is a security control as much as an audit feature: it means the integrity of your evidence does not depend on our continued availability, our continued good behaviour, or our continued existence.
If you need the specifics — sub-processors, incident response timelines, tenancy architecture, or a security questionnaire filled in — ask. We are early enough that the honest answer to some questions is that a control is planned rather than implemented, and we will tell you which.
We are a two-person company and we will not pretend to a compliance posture we have not earned.
What we can defend is the architecture: read-only, customer-tenancy, short raw retention, append-only logging, and evidence that verifies without us.
Want this pointed at your fleet?
We are onboarding fleets and repair networks a few at a time. Tell us what you run and we will reach out.