
Point cloud data is an exact record of your facilities, infrastructure, and sites, which makes it a highly confidential asset. For TENZOH, our point cloud viewer, security itself is the greatest value we deliver.
Principles
TENZOH doesn't rely on a single control. It layers several independent defenses, and we run our own system that keeps checking, continuously and automatically, whether those defenses are holding.
Authentication, permissions, encryption, network, application, and monitoring each defend as an independent layer.
Even if one layer is breached, the whole system stays protectedWe grant every user and every component only the permissions they need.
If something does go wrong, the impact stays containedIf something is misconfigured or goes wrong, the system fails closed, not open.
A failure ends in downtime, not a data leakWe don't stop once a control is in place. We keep testing it.
Quality does not degrade over timeMeasures
We keep tight control over who can get in.
We protect your data by keeping it structurally separate from every other organization's.
We apply industry-standard defenses in multiple layers against the common attacks aimed at web applications.
We build in safeguards that keep the system from being broken or driven into a runaway state.
Visible now. Traceable later.
Sharing Policy
For confidential data, we recommend sharing by invitation instead of relying on public links.
Security Assurance
What sets TENZOH apart is that we don't secure it once and call it done. Recmill runs the RECMILL Security Assurance Platform, a verification system we built ourselves to hold security quality steady over time. Every month it runs the same cycle automatically: verify, record, publish, and strengthen.
We verify our core security commitments automatically, every month. The same checks run on every change we ship, so regressions get caught.
We build up a history of verification results. Every check leaves a record of what was verified and when.
We share the results with you, past runs included. You can confirm for yourself that the commitments are holding.
We fix what we find, most serious first, and keep strengthening our controls.
We test TENZOH from an attacker's point of view, again and again, and fix what we find right away.
We verify our security commitments with automated checks.
We run the checks every month and share the results, past runs included.
We keep checking the third-party components we use for known risks and fix them early.
This is how we run TENZOH. Automated checks confirm, continuously, that its security commitments are holding right now.
Operation
Note: This page is an overview written for customers. The measures described here are strengthened and updated on an ongoing basis. We do not publish implementation details, to keep them from being copied or abused.