Security and data
Built to run inside your building and answer to your IT team.
Smart Tenants is a building system first and a cloud service second. This page describes how it is put together so your IT and security people can judge it for themselves.
On site by design
Readings, history, checks and control stay on a server in your building. The cloud receives conditions, reports and backups.
Outbound only
The site connects out to our cloud over mutual TLS. Nothing is opened inbound to your network.
Every site has its own identity
Each installation holds a device certificate issued at registration and renewed automatically on a short cycle.
Signed software
Every release is signed, and a site verifies the signature against a root it already trusts before applying it.
Least privilege
Roles decide who can see and who can change. Writing to equipment needs an explicit permission, and every write is recorded.
The AI reads. It does not control.
AI writes reports from building data. It never changes a setpoint, and it can be switched off per site.
Where your data lives
On site, with a defined set of things sent to the cloud.
The Tapa Framework runs on a small server on your network. It reads your building management system, controllers and meters directly and keeps live values, point history, equipment checks and alarms there. If the internet connection drops, the building keeps being watched and the history keeps being kept.
What the cloud receives is deliberate and limited: the conditions the checks found and their evidence, the reports generated from them, telemetry about the installation itself, and configuration backups. Backups never include the site's private keys. Data in our cloud is encrypted in transit and at rest.
Ownership and retention of building data are set out in your agreement with Smart Tenants, LLC, not by this page.
Connections
Outbound, mutually authenticated, renewed on a schedule.
The site opens the connection to our cloud, never the other way round, so no inbound port is needed on your firewall. Both ends present certificates: the site holds a device certificate issued when it is registered, and our services accept only the current one for that installation. Certificates are renewed automatically on a short cycle, so a copied key stops working on its own rather than living for years.
When our engineers need to reach a site for support, the session is brokered by our cloud, requires sign-in, is bound to one person and one target, and is logged. There is no standing remote-access path into the building.
On the building side, the server speaks the protocols your equipment already uses. It can be installed as a read-only observer, and writing to equipment is a permission that has to be granted.
Software integrity
Signed, verified, released by channel.
Every release is signed with a certificate that chains to a root held in a hardware-protected key store, and a site verifies that chain before applying an update. If a signing key ever had to be replaced, a new one would be issued under the same root without touching any site.
Updates are published to release channels and applied under our control; nothing is fetched from third parties at run time. There is no third-party plugin ecosystem: all code that runs on the site is ours and ships with the release. Before a release, the server is exercised by a dedicated hardening suite that sends it malformed and hostile input across every protocol and API it exposes.
Access control
Roles for seeing, a permission for changing, a record of both.
Users are assigned roles. Viewing roles see; operator and administrator roles can change configuration and, with an explicit permission, write to equipment. Every write to a point or a setting is recorded with who made it and when, and the record is available to you.
Insight, the owner's view, is read-only by design. Executive reports carry no controller paths or point names; the engineering briefing does, because engineers find equipment by them.
How the AI is used
A reader of building data, with an off switch.
AI is used for one thing: reasoning over the conditions, history and equipment facts of a site to write reports. It does not control equipment, it does not change setpoints, and it does not act on the building. Where supervisory optimisation is enabled, that is deterministic logic with limits you set, and it starts in a monitor-only mode so you can see what it would do before it does anything.
Model calls are made from our cloud, in our account, through Amazon Bedrock. Amazon states that Bedrock does not use customer inputs or outputs to train models. Each site has an AI switch: turn it off and every AI feature degrades cleanly to its deterministic equivalent while alarms, checks and history carry on unchanged. Usage is metered against your plan, so there are no surprises.
Operations
Watched by us, too.
The fleet of installations is audited automatically every day for certificate and identity anomalies, and findings come to us in plain language. A site that goes quiet raises an alert. Support packages a site produces for us exclude its private keys. We keep the cloud side small, in one region, with the same signed-release discipline as the site software.
We do not hold third-party certifications today and do not claim to. Ask us anything on this page and we will walk your IT and security teams through it directly at sales@smtn.ai.
Questions for your security review?
Tell us about your building systems and we will show you what a morning briefing would say.