The standard behind the software
AI in a regulated industry has to show its work. The seven engineering criteria every Beacon feature meets, the seven limits the AI is held to, and how the models and your data are governed. Each one checkable in the product.
Beacon was built and tested inside a working SQF-certified facility, where a missed citation or a quietly changed record is an audit finding, not a bug ticket. This page is the rubric we hold ourselves to. We publish it so you can hold us to it too.
What every Beacon feature has to meet
Not aspirations. A rubric applied before anything ships, from the citation on an AI suggestion to the export path on a new module.
The build rubric
7 criteria
Every output cites its source
Each AI suggestion, automation, and workflow names the clause or standard it serves: SQF, 21 CFR, Codex, OSHA, FSIS. If we cannot cite it, we do not surface it.
Every AI write leaves evidence
Every AI write to a tenant record persists to an append-only evidence trail and the activity log, aligned to ALCOA+. You can see what the AI did, what it read, and who signed off.
Humans approve by default
AI drafts; people decide. No hazard is classified, no product released, and no supplier approved without a human signature.
Provenance on every AI artifact
The model, the prompt version, the retrieved sources, and the reviewer's decision are frozen at the moment of decision, including a language-equivalence attestation on translated training records.
Regulatory records are immutable
Published HACCP plans, SOPs, and signed forms cannot be quietly changed. Operational fields soft-edit; the record of record does not.
Built for the floor
Floor forms queue writes through brief connectivity drops and sync on demand. Capture is designed around real plant conditions, not office wifi.
Audit-ready from day one
Every module ships with an audit-export path when it goes live, not as a later add-on.
What Beacon won't do
Won't auto-release a lot
Release decisions require a human signature, every time.
Won't auto-classify a hazard
Hazard analysis is AI-drafted and PCQI-approved. The judgment stays yours.
Won't auto-approve a supplier
Supplier approval is a human decision, not an algorithm's.
Won't train on your data
Your tenant data never trains a shared model. No cross-tenant learning, period.
Won't share data across tenants
The architecture enforces isolation; the policy commits to it.
Won't recommend without showing its work
Every safety-relevant output carries an evidence record with its source documents. If Beacon cannot show its work, it does not make the recommendation.
Won't change silently
The prompt version and model are recorded on every write. The AI Transparency section below covers how we handle changes.
Hold us to it
These limits are this page's contract. If you ever see Beacon cross one, tell us: hello@systempath.com.
The models we use, and what your data is used for
Straight answers to the questions QA teams and security reviewers ask about AI in Beacon. If your review needs more depth than this page, ask us: we walk security teams through the specifics under NDA.
Beacon routes each AI task to the model suited to it. Model selection is a configuration decision under change control, and the model behind every AI write is recorded on the evidence record, so a change is visible in your own audit trail, never silent.
-
Never trains a shared model
Your tenant data is not used to train models, ours or anyone else's. No cross-tenant learning, period.
-
Isolated per tenant
Every AI query is scoped to your tenant at the database layer, and a dedicated isolation test suite asserts it on every build.
-
Encrypted and redacted
Data is encrypted at rest, and personal identifiers are redacted before any diagnostic trace leaves the system.
What's stored, and who controls it
Conversations
Chat history with the assistant stays in your account for its lifetime.
Extracted memory
Facts the assistant remembers about your operation. Viewable, and deletable from settings at any time.
Evidence trail
The append-only record of every safety-relevant AI action. Never edited, never deleted.
Document embeddings
A search index over your documents, rebuilt when a document changes.
You hold the switches
Tenant administrators can turn off agent memory, background AI insight generation, and automatic image analysis from settings, and clear stored memory entirely. Questions about AI data handling: privacy@systempath.com.
Running a formal vendor or security review? We answer the detailed questionnaires and walk your security team through the architecture, with the engineers who built it, not a sales script.
See it in the product.
A 20-minute walkthrough scoped to your facility, your certifications, and your audit calendar. Not a pitch deck.
Prefer the phone? (313) 484-4887
What happens next
Discovery call
About your facility and goals. Not a sales pitch.
See it in action
A live walkthrough of Beacon scoped to your operation.
Custom proposal
Software, consulting, and training sized to your facility.
You'll talk with a food safety expert, not a sales rep.
20 minutes · No commitment · No pressure
Questions about AI in Beacon.
Answers from the team that runs Beacon inside a working SQF-certified plant.
No. Your tenant data never trains a shared model, ours or anyone else's, and there is no cross-tenant learning. The assistant does remember facts about your operation to be useful, and that memory is yours: viewable, and deletable from tenant settings at any time.
Beacon routes each task to the model suited to it, across Anthropic Claude, OpenAI, Google Gemini, and Voyage AI. Model selection is a configuration decision under change control, and the exact model behind every AI write is recorded on its evidence record, so a model change shows up in your own audit trail rather than happening silently.
The parts that act on their own, yes. Tenant administrators can disable agent memory, background insight generation, and automatic image analysis from settings, and clear stored memory entirely. And whatever stays on, the AI only drafts: releases, hazard classifications, and supplier approvals always require a human signature.
A complete record. Every safety-relevant AI action writes an append-only evidence entry: the model that ran, the sources it read, what it did, and the human reviewer's signed decision. Records are never updated and never deleted, so the trail you show an auditor is the trail as it happened.