AI Security
There are two ways AI is used with your MachineMetrics data, and they have different security models:
- AI built into the MachineMetrics platform — Max AI, and AI-assisted features such as Shift Handover. Processing happens inside our private AWS environment.
- Your own AI assistant — a tool such as Claude Code or Claude Desktop that you connect to MachineMetrics tools using MCP. Processing happens with the AI provider you chose.
Both are legitimate ways to work. The difference determines which company's agreement governs your data once a question is answered, so this page covers each in turn.
The difference at a glance
| MachineMetrics platform AI | Your own assistant (MCP) | |
|---|---|---|
| Who runs the AI model | MachineMetrics, on AWS Bedrock | Your AI provider (for example, Anthropic or OpenAI) |
| Where inference happens | Inside our private AWS tenant | In your provider's environment |
| Where your data goes | Stays within MachineMetrics infrastructure | Tool results are sent to your provider to answer your question |
| Whose terms govern that processing | Your MachineMetrics agreement | Your agreement with that provider |
| How access is controlled | Your MachineMetrics login and permissions | Your MachineMetrics login and permissions, via OAuth |
| Used to train models? | No | Governed by your provider's policy, not ours |
| Who decides to enable it | Available in the platform | You choose to connect it |
If your company's policy prohibits sending production data to external AI providers, use the AI built into the platform and do not connect an external assistant. If you have an agreement with an AI provider that permits it, connecting your own assistant gives you the flexibility of your own tools.
Part 1 — AI built into the MachineMetrics platform
Everything in this part applies to all AI features built into the platform, including:
- Max AI — the natural language interface described below
- AI-assisted Shift Handover — structures an operator's shift notes into a summary for the incoming operator (guide)
All of them run on foundation models via AWS Bedrock inside our private AWS tenant. None of them send your data to an external AI provider.
Max AI
Max AI is MachineMetrics' natural language interface for production intelligence. Users ask questions in plain English and receive contextual, data-driven answers — surfacing downtime drivers, cost breakdowns, and performance trends without dashboards or technical skills. For how to use it, see the Max AI Guide.
Security & privacy overview
MachineMetrics AI is designed with privacy, scalability, and security at the forefront. Platform AI capabilities operate entirely within our private AWS infrastructure using a robust agentic architecture and foundation models via AWS Bedrock.
Cloud-native AI via AWS Bedrock
Platform AI features are built on AWS Bedrock, which provides access to foundation models while maintaining enterprise-grade controls. We exclusively use models via AWS Bedrock, ensuring that:
- Your data stays inside the MachineMetrics environment. Inputs and model responses are processed by AWS Bedrock within our AWS environment, in the region our platform runs in. AWS is our cloud provider and a listed sub-processor
- No AI provider outside that environment receives your data. We send nothing to an AI vendor's own service — Anthropic's or OpenAI's APIs, for example — and the providers whose foundation models we run on Bedrock do not receive your inputs or your model responses
- This approach supports data sovereignty and security for industrial workflows
This applies to Max AI and other AI features built into the MachineMetrics platform. It does not describe what happens when you connect your own AI assistant to MachineMetrics tools — that assistant runs on your provider's infrastructure. See Part 2.
Agentic architecture within a Virtual Private Cloud
MachineMetrics employs an agentic architecture hosted inside the same Virtual Private Cloud (VPC) that houses our core application infrastructure. This architecture orchestrates:
- Multi-step reasoning workflows
- Intelligent task decomposition
- Dynamic model selection and routing
These agents are containerized, stateless, and operate in an isolated manner, ensuring secure and auditable interactions with customer data.
Models in use
Max AI invokes foundation models made available through AWS Bedrock. Model selection is dynamically managed by our agentic architecture, ensuring that all inference is performed securely within our private cloud. This strategy maintains our commitment to data privacy, compliance, and performance.
Effective August 25, 2026, Anthropic models are not in use for MachineMetrics GovCloud customers. Platform AI features on GovCloud run on different foundation models, still via AWS Bedrock inside our environment.
This describes which models MachineMetrics uses to power platform AI. It does not restrict which AI assistant you connect to our MCP server — GovCloud customers can connect any MCP-compatible client, including Claude. If you do, the data path is the one described in Part 2: tool results go to whichever provider runs the assistant you chose, under your agreement with them. That is worth weighing against your own compliance obligations.
Inference security and privacy
All Max AI inference happens within our private AWS tenant. Specifically:
- Customer prompts, telemetry, and any derived artifacts remain isolated
- Inference logs are stored in compliance with our internal security policies
- No customer data is used to train or fine-tune models
This control mechanism aligns with the security expectations of enterprise manufacturing customers and privacy requirements such as GDPR.
How platform AI data flows
┌─────────────────┐ ┌──────────────────┐ ┌────────────────────┐
│ Your Data │────▶│ MachineMetrics │────▶│ AWS Bedrock │
│ (in our VPC) │ │ AI Agents │ │ (in our VPC) │
└─────────────────┘ └──────────────────┘ └────────────────────┘
│
▼
Results returned
(data stays in VPC)
Part 2 — External AI assistants using MCP tools
MachineMetrics publishes an MCP server, a standard way for an AI assistant to use external tools. If you connect your own assistant — Claude Code, Claude Desktop, or another MCP-compatible client — it can query your production data and search your Knowledge Hub on your behalf. See Connect an AI Assistant with MCP for setup.
This is opt-in. Nothing is connected until someone at your company chooses to connect it.
How access is granted
Connections use OAuth, the standard sign-in flow you have seen when an application asks to connect to Google or Microsoft.
- You sign in with your own MachineMetrics account and approve the connection in your browser.
- No API key or password is entered into the AI assistant. OAuth gives the client an access token to call MachineMetrics; your MachineMetrics password is never shared with the assistant or its provider.
- Access is granted per user, not per company. Each person connects their own assistant with their own account.
- Access tokens are short-lived and the assistant renews them for you. You are asked to sign in again only if access is revoked or the assistant is reconnected.
- You can revoke it at any time — open your MachineMetrics account settings, find Authorized Apps, and click Revoke Access on the assistant. It will be asked to sign in again the next time it connects. Removing the connector in the assistant itself also stops it being used.
What a connected assistant can reach
Your permissions apply, unchanged. A connected assistant acts as you, scoped to your company. It can reach the data your MachineMetrics account can reach and nothing more. It cannot see another company's data, and it cannot perform actions your account is not permitted to perform.
Which tools it sees is decided per person. The set is assembled from your role in MachineMetrics and the access you granted that assistant when you signed in, so two people at the same company can see different tools, and different numbers of them.
The core tools only read. They retrieve and query information — production metrics, operational data, Knowledge Hub documents. They do not change machine settings, control equipment, or modify production records.
Tools added by other MachineMetrics products can write within that product. Where your company uses a product that adds its own tools, some of them create or change that product's own data, such as publishing a schema or seeding records for a custom application. None of them changes machine settings or controls equipment, and each is still bound by your role and by what you granted at sign-in.
Every request is authenticated and logged. Tool calls are authorized against your account's permissions and recorded in our audit trail, the same as other authenticated access to your data.
What leaves the MachineMetrics environment
This is the part that differs most from Max AI, and it deserves to be stated plainly.
When your assistant calls a MachineMetrics tool, the tool returns your data to the assistant you are running. That assistant then sends the data to its own provider in order to answer your question. From that point, the data is handled under your agreement with that provider, including their policies on retention, human review, and whether data is used to improve their models. MachineMetrics is not a party to that processing and cannot control it.
What MachineMetrics controls: who may connect, what a connection may access, and the record that it happened. What your provider controls: everything that happens after the data reaches them.
How external assistant data flows
┌─────────────────┐ ┌──────────────────┐ ┌────────────────────┐
│ Your Data │────▶│ MachineMetrics │────▶│ Your AI assistant │
│ (in our VPC) │ │ MCP server │ │ (on your machine) │
└─────────────────┘ └──────────────────┘ └────────────────────┘
OAuth: your account, │ │
your permissions │ ▼
│ ┌────────────────────┐
Access logged │ Your AI provider │
│ (outside our VPC) │
└────────────────────┘
Governed by your
agreement with them
Your responsibilities when connecting an assistant
Because this path involves a provider we do not control, a few things sit with you:
- Confirm it fits your data-handling policy before connecting, and check whether your agreement with your AI provider covers production data.
- Connect with an account whose permissions match your intent. An assistant connected with a broad account can reach broadly.
- Treat the assistant as you would any application with your access — keep it on managed devices, and disconnect it when someone leaves the team or changes role.
- Review connections periodically, the same way you review API keys and user accounts.
Frequently asked
Does connecting an assistant give MachineMetrics access to my AI provider account? No. The connection runs one way: your assistant asks MachineMetrics for data. We receive no access to your assistant, your provider account, or your other conversations.
Can we allow MCP access for some people and not others? Access is already differentiated per person, through the controls you use for everything else. A connected assistant is bound by that person's role in MachineMetrics and by the access they granted it at sign-in, so it can never reach more than their account allows, and two people with different roles get different access. There is no separate on and off switch for MCP, because the accounts and roles you already manage are the control. If your organization needs something beyond that, contact support@machinemetrics.com so we can look at your situation.
Does data sent to an external provider get used to train their models? That is determined by your agreement with that provider, not by MachineMetrics. Providers generally do not train on business or API traffic by default, but you should verify this against your own contract.
Can we prevent external assistants from connecting at all? Talk to us. Connecting requires a MachineMetrics account, so access is bounded by the accounts and permissions you already control. If your organization needs MCP access restricted more broadly than that, contact support@machinemetrics.com so we can advise on the right control for your situation.
Summary
MachineMetrics delivers AI in two forms with two security models, both under your control.
AI built into the platform — Max AI and AI-assisted features such as Shift Handover — keeps everything inside our environment: foundation models via AWS Bedrock, full isolation within our VPC, no AI provider outside that environment involved, and no customer data used for training. It is the right choice when data must not leave our platform.
External assistants over MCP let you use the AI tools you already have, with access governed by your own MachineMetrics login and permissions and every request logged. In exchange, your data reaches the AI provider you chose and is governed by your agreement with them. It is the right choice when that trade is one your company has decided to make.
Related Articles
- Connect an AI Assistant with MCP — Setup guide for external assistants
- Data Handling & Privacy — Data ownership, cloud storage
- Edge Device Security — Edge transmission and device security
- Security Overview — Encryption, authentication, certifications
- Max AI Guide — How to use Max AI
- Shift Handover — AI-assisted operator handover notes