Security at PICSEL

PICSEL helps industrial organisations run an OT cybersecurity program. That means we handle chat, workspace facts, and programme artefacts that can include sensitive operational context. This page explains how we protect that data today.

Honest scope: this describes our current product controls. It is not a SOC 2, ISO 27001, or third-party audit report.

Data we store

SurfaceWhat’s storedWho it’s for
Free advisor (picsel.ai home page chat box)Chat messages on a shared public workspaceAnyone trying PICSEL
Company workspace (app.picsel.ai)Chats, site/company facts, keepable artefacts (e.g. charter / CSMS / playbook drafts), memberships, invitesYour signed-in company
Account identitySign-in identity via Clerk (membership keyed on Clerk user id)Workspace users

We use this data to run the product and improve answers. We do not sell customer chat content.

How company data stays separated

  • Each company gets its own workspace tenant.
  • Data access is scoped from your signed-in membership — the app does not let the browser pick another company’s id.
  • Public free chats, internal test chats, and company workspaces use separate tenants.
  • If you move from trial to paid, we keep you on the same company workspace so chats and artefacts stay with you.

Who can see what

  • Your team: only people you invite into your company workspace, after they sign in.
  • PICSEL operators: a tightly limited platform admin path for running the service (review, support, reliability). Company membership alone does not grant that access.
  • Optional email: documents are only emailed after you confirm in chat.

Infrastructure partners

Vercel · Neon (Postgres) · Clerk · Resend · AI answers: configured model provider(s), primarily xAI (prompt context to answer).

Secrets in hosting env, not git.

What this page does not claim

  • Independent penetration testing or certification attached to this page
  • That free public chats are private company workspaces (they are shared by design)
  • That AI providers never see prompt content (they must, to generate answers)
  • Field-level encryption beyond our providers’ standard protections

Questions or human help

For product security questions, contact us at hello@picsel.ai

If you need hands-on OT cybersecurity advisory beyond the software, you can engage NetSeg (Leon Poggioli).

Practical guidance. Plant-centric. Security that scales.

picsel.ai · Human OT advisory: NetSeg