Skip to main content

SQF Edition 10 audits start January 2027. Is your program ready? Learn more →

How Beacon is built

The standard behind the software

AI in a regulated industry has to show its work. The seven engineering criteria every Beacon feature meets, the seven limits the AI is held to, and how the models and your data are governed. Each one checkable in the product.

Why we publish this

Beacon was built and tested inside a working SQF-certified facility, where a missed citation or a quietly changed record is an audit finding, not a bug ticket. This page is the rubric we hold ourselves to. We publish it so you can hold us to it too.

Seven engineering criteria

What every Beacon feature has to meet

Not aspirations. A rubric applied before anything ships, from the citation on an AI suggestion to the export path on a new module.

The build rubric

7 criteria

01

Every output cites its source

Each AI suggestion, automation, and workflow names the clause or standard it serves: SQF, 21 CFR, Codex, OSHA, FSIS. If we cannot cite it, we do not surface it.

02

Every AI write leaves evidence

Every AI write to a tenant record persists to an append-only evidence trail and the activity log, aligned to ALCOA+. You can see what the AI did, what it read, and who signed off.

03

Humans approve by default

AI drafts; people decide. No hazard is classified, no product released, and no supplier approved without a human signature.

04

Provenance on every AI artifact

The model, the prompt version, the retrieved sources, and the reviewer's decision are frozen at the moment of decision, including a language-equivalence attestation on translated training records.

05

Regulatory records are immutable

Published HACCP plans, SOPs, and signed forms cannot be quietly changed. Operational fields soft-edit; the record of record does not.

06

Built for the floor

Floor forms queue writes through brief connectivity drops and sync on demand. Capture is designed around real plant conditions, not office wifi.

07

Audit-ready from day one

Every module ships with an audit-export path when it goes live, not as a later add-on.

Seven limits

What Beacon won't do

Won't auto-release a lot

Release decisions require a human signature, every time.

Won't auto-classify a hazard

Hazard analysis is AI-drafted and PCQI-approved. The judgment stays yours.

Won't auto-approve a supplier

Supplier approval is a human decision, not an algorithm's.

Won't train on your data

Your tenant data never trains a shared model. No cross-tenant learning, period.

Won't share data across tenants

The architecture enforces isolation; the policy commits to it.

Won't recommend without showing its work

Every safety-relevant output carries an evidence record with its source documents. If Beacon cannot show its work, it does not make the recommendation.

Won't change silently

The prompt version and model are recorded on every write. The AI Transparency section below covers how we handle changes.

Hold us to it

These limits are this page's contract. If you ever see Beacon cross one, tell us: hello@systempath.com.

AI Transparency

The models we use, and what your data is used for

Straight answers to the questions QA teams and security reviewers ask about AI in Beacon. If your review needs more depth than this page, ask us: we walk security teams through the specifics under NDA.

Anthropic Claude OpenAI Google Gemini Voyage AI

Beacon routes each AI task to the model suited to it. Model selection is a configuration decision under change control, and the model behind every AI write is recorded on the evidence record, so a change is visible in your own audit trail, never silent.

  • Never trains a shared model

    Your tenant data is not used to train models, ours or anyone else's. No cross-tenant learning, period.

  • Isolated per tenant

    Every AI query is scoped to your tenant at the database layer, and a dedicated isolation test suite asserts it on every build.

  • Encrypted and redacted

    Data is encrypted at rest, and personal identifiers are redacted before any diagnostic trace leaves the system.

What's stored, and who controls it

Conversations

Chat history with the assistant stays in your account for its lifetime.

Extracted memory

Facts the assistant remembers about your operation. Viewable, and deletable from settings at any time.

Evidence trail

The append-only record of every safety-relevant AI action. Never edited, never deleted.

Document embeddings

A search index over your documents, rebuilt when a document changes.

You hold the switches

Tenant administrators can turn off agent memory, background AI insight generation, and automatic image analysis from settings, and clear stored memory entirely. Questions about AI data handling: privacy@systempath.com.

Security reviews

Running a formal vendor or security review? We answer the detailed questionnaires and walk your security team through the architecture, with the engineers who built it, not a sales script.

Detail

Under NDA

You talk to

The build team

Talk to an expert

See it in the product.

A 20-minute walkthrough scoped to your facility, your certifications, and your audit calendar. Not a pitch deck.

Prefer the phone? (313) 484-4887

What happens next

01

Discovery call

About your facility and goals. Not a sales pitch.

02

See it in action

A live walkthrough of Beacon scoped to your operation.

03

Custom proposal

Software, consulting, and training sized to your facility.

You'll talk with a food safety expert, not a sales rep.

20 minutes · No commitment · No pressure

FAQ

Questions about AI in Beacon.

Answers from the team that runs Beacon inside a working SQF-certified plant.

No. Your tenant data never trains a shared model, ours or anyone else's, and there is no cross-tenant learning. The assistant does remember facts about your operation to be useful, and that memory is yours: viewable, and deletable from tenant settings at any time.

Beacon routes each task to the model suited to it, across Anthropic Claude, OpenAI, Google Gemini, and Voyage AI. Model selection is a configuration decision under change control, and the exact model behind every AI write is recorded on its evidence record, so a model change shows up in your own audit trail rather than happening silently.

The parts that act on their own, yes. Tenant administrators can disable agent memory, background insight generation, and automatic image analysis from settings, and clear stored memory entirely. And whatever stays on, the AI only drafts: releases, hazard classifications, and supplier approvals always require a human signature.

A complete record. Every safety-relevant AI action writes an append-only evidence entry: the model that ran, the sources it read, what it did, and the human reviewer's signed decision. Records are never updated and never deleted, so the trail you show an auditor is the trail as it happened.