Introducing RAMS AI Vision — Intelligent Warehouse Perception

Certifications & security

Trust must be
demonstrable.

The standards, assurance evidence and security practices supporting RAMS Digital — before operational data becomes part of the platform.

SOC 2 Type I publicly statedStandards-aligned workflowsScope-conscious claims

AICPA SOC 2SOC 2
AICPA SOC 2 Type ISOC 2 · Type I
BadgeCertification 03
BadgeCertification 04
BadgeCertification 05
BadgeCertification 06
BadgeCertification 07

Trust posture

One trust posture.
Four distinct questions.

Certifications matter, but enterprise trust also depends on how controls operate, how standards are applied and what the contract actually commits to.

01 · Assurance

What has been independently examined?

SOC 2 Type I provides an external view of control design at a defined point in time.

Independent evidence
02 · Operations

Which standards shape the work?

Standards such as EN 15635 inform rack inspection, classification, rectification and verification workflows.

Standards alignment
03 · Platform

How is access and data governed?

Identity, permissions, integrations, auditability and data handling are reviewed against the intended deployment.

Security posture
04 · Contract

What is committed for your service?

Availability, support, hosting, residency, retention and recovery targets must be confirmed for the agreed scope.

Customer-specific
AICPA SOC 2 Type I
Type I · Publicly stated

Certification & assurance

A control claim
Buyers can examine.

RAMS Digital publicly states SOC 2 Type I certification. Type I evaluates whether relevant controls are suitably designed at a specific point in time; it is different from a Type II report, which examines operating effectiveness over a period.

  • Ask for the current report period

    Assurance is time-bound and should be reviewed for recency.

  • Confirm the system boundary

    Identify the products, infrastructure and processes included.

  • Review exceptions and complementary controls

    Understand what RAMS controls and what remains with the customer.

Standards alignment

A standard only creates value
When it changes the workflow.

RAMS connects inspection evidence, asset context and corrective actions so safety standards can become an operational process — not a static certificate.

Rack safety · EN 15635

From inspection to verified closure.

Support competent inspection programmes with digital records linked to racks, bays, locations and actions.

  1. Inspect

    Capture evidence

    01
  2. Classify

    Apply risk logic

    02
  3. Assign

    Create action

    03
  4. Rectify

    Record repair

    04
  5. Verify

    Close with evidence

    05
Important distinction

Alignment is not accreditation.

EN 15635 can inform a rack-safety programme. It does not certify the software, the site or the customer by itself.

Standard

Defines recognised practice

Competence

Applies to people and roles

Platform

Structures records and workflow

Customer

Owns site compliance duties

Security architecture

Protection across identity,
Data and operations.

The assurance conversation should cover the whole operating chain — from a user opening the platform to a sensor or business system exchanging data.

ID

Identity & access

Govern who can access each organisation, site, module and function.

  • Role and site-level access
  • Privileged-action governance
  • User lifecycle and periodic review
APP

Application security

Define secure configuration, change control and vulnerability handling.

  • Release and change governance
  • Security testing evidence on request
  • Controlled administrative functions
DATA

Data protection

Map operational and personal data before agreeing controls.

  • Data flows and ownership
  • Retention, export and deletion
  • Encryption requirements verification
API

Integrations

Limit machine-to-machine access to what each workflow needs.

  • Interface and credential inventory
  • Least-privilege access
  • Error, event and change monitoring
LOG

Monitoring & response

Connect suspicious activity to a defined triage and escalation process.

  • Event visibility
  • Incident ownership and escalation
  • Customer notification terms
BC

Continuity

Agree service resilience targets appropriate to the deployment.

  • Back-up and recovery scope
  • RTO/RPO confirmation
  • Availability and support terms

Control register

Published, configurable
Or contractual.

That distinction keeps security statements accurate — and gives procurement teams a faster route to the evidence they need.

Publicly stated

SOC 2 Type I

How to evaluate it

Request current report details, scope and exceptions.

Configurable

Roles, sites & modules

How to evaluate it

Validate the permission matrix during implementation.

Workflow-based

Operational audit history

How to evaluate it

Confirm which user, asset, event and change histories are retained.

Scope-specific

Hosting & data residency

How to evaluate it

Agree regions, subprocessors and international transfer requirements.

Contract-specific

Availability, support & recovery

How to evaluate it

Confirm SLA, support hours, back-up policy, RTO and RPO.

Verify design

Authentication controls

How to evaluate it

Confirm MFA, federation, session and password requirements for your environment.

Data protection

Start with the data flow,
Not the checkbox.

A useful security review identifies what the platform receives, why it is needed, where it moves, who can access it and how long it should remain.

01

Discover

Inventory operational, device, user and personal data.

02

Classify

Separate sensitive and business-critical information.

03

Control

Set access, retention, sharing and export rules.

04

Verify

Review the implemented configuration and evidence.

Evidence & traceability

From verbal updates
To attributable evidence.

Operational records become more useful when they connect the person, action, time, site and physical asset — instead of being scattered across email, spreadsheets and presentations.

The principle

Data shows what changed. Context shows where, why and by whom.

PersonActionTimeSiteAsset
Site 03 · Assurance activityIllustrative activity
  • Access scope updatedRegional safety lead · Sites 03–0509:42
  • Inspection evidence verifiedRack B-14 · Action AC-220808:17
  • Integration credential rotatedWMS production connectorYesterday
  • Quarterly permission review closed2 access changes approved04 Sep

Integrations & third parties

Connected intelligence needs
Controlled interfaces.

RAMS can integrate with operational and enterprise systems. Each connection should have a named owner, defined purpose, limited permissions and monitored credentials.

WMS / ERP / MES
CMMS / TMS / HRMS
Sensors / cameras / edge
Customer APIs
RAMS DigitalGoverned integration boundary

Purpose-bound access

Only the data required for the use case

Credential control

Issue, store, rotate and revoke

Change visibility

Know when an interface changes

Failure handling

Detect, retry, alert and investigate

Privacy & governance

Compliance is shared,
Scoped and jurisdiction-specific.

RAMS can support controlled data handling, but no software platform makes a customer automatically compliant. The applicable law, roles and obligations depend on the deployment.

Customer

Customer decisions

Purpose, lawful basis, workforce notices, internal access and acceptable use.

RAMS

Platform commitments

Agreed processing, security measures, subprocessors and support for data requests.

Together

Joint verification

Data-flow review, contractual roles, retention schedule and go-live approval.

Resilience

Define recovery
Before it is needed.

A production deployment should translate availability expectations into explicit architecture, recovery targets, incident ownership and communication paths.

Availability

Agree service hours, exclusions, dependencies and measurement method in the applicable service terms.

Recovery

Confirm back-up coverage, recovery point and recovery time objectives for the chosen scope.

Incident response

Document triage, severity, escalation, notification, investigation and post-incident review.

Implementation

Security is configured
With the operation.

Move from diligence to production through a controlled implementation path.

01

Discover

Define use case, data, users and risk.

02

Map

Document systems, flows and responsibilities.

03

Configure

Set roles, sites, workflows and retention.

04

Validate

Test controls, integration and recovery expectations.

05

Review

Approve go-live and schedule assurance reviews.

Customer assurance pack

A clear route
To diligence.

Request the evidence relevant to your assessment. The exact materials available may depend on confidentiality, deployment scope and approval.

On request

SOC 2 Type I evidence and scope

The report details, period, system boundary, exceptions and complementary customer controls.

Diligence

Security questionnaire response

Answers to your own diligence questionnaire, against the deployment being proposed.

Scope-based

Architecture and data-flow overview

What the platform receives, why, where it moves and who can reach it.

Contract

Data processing and subprocessor details

Processing terms, subprocessors, residency and international transfer requirements.

Implementation

Roles and permission matrix

The organisation, site, module and function-level access model as configured for you.

Service terms

Incident and escalation process

Triage, severity, ownership, notification terms, investigation and post-incident review.

Frequently asked questions

Clear answers.
No badge inflation.

RAMS Digital publicly states SOC 2 Type I certification. Buyers should request the current report details and confirm its period, scope, exceptions and complementary customer controls.

Enterprise assurance

Build on a foundation
you can examine.

Review the evidence. Confirm the scope. Map the data. Configure the controls. Then deploy with trust designed into the operating model.