Skip to content
Trust & Governance

Evidence before action.

This is how HeatAssure™ deployments are governed. Every number traces to the record that produced it. Every outbound action needs approval and lands in a journal that keeps its history. Your deployment runs in its own tenancy, the data and IP boundaries are written into the contract, and the evidence you build up is yours to take with you.

Provenance

What every recommendation shows.

Before any team acts, they can see what triggered the recommendation, what supports it, how confident the platform is, and what happens next. Every input, and the confidence attached to it, is named on the record.

01

Drivers

What triggered this recommendation? Survey evidence, sensor data, weather, a change in the home: every input is named.

02

Evidence

What data supports it? Raw readings, derived results and domain context are linked so nothing is taken on faith.

03

Confidence

How sure are we? A confidence score with stated bounds, not a hidden probability. You see when the platform is uncertain.

04

Action

What should happen next? A concrete, reversible step, with rollback conditions defined before execution.

As shipped
  • A live governed platform: every screen resolves against a governed viewpoint, and every claim carries its validation status, including the red ones.

The red ones are the claims that do not yet pass. Failure stays visible until it is fixed.

Policy

You set the policy.

HeatAssure runs at the level of autonomy you set, through three policy settings: Assist, Govern and Auto. They set how much runs before a person is involved, and every deployment starts on Assist.

Assist

Every recommendation waits for a person. The platform shows its evidence; your team decides and acts.

Govern

Actions run inside bounds agreed in advance. Escalations and edge cases stay with people.

Auto

Approved action types run without waiting, under the same journal, with rollback conditions defined before anything moves.

Changing the setting is a policy change you make, against quality gates agreed jointly and evidence that each action type can be reversed.

Boundaries

Data & IP boundaries.

01

Customer data stays with the customer

Raw data is processed in isolated per-customer tenants. Anything that could identify you, your homes or your products stays inside your tenancy; under each customer’s contract licence the record learns in de-identified aggregate, and that accumulated learning is part of what every customer buys.

02

Evidence is portable

Evidence packs and audit trails export in human-readable and machine-readable formats.

03

No lock-in

Cancelling ends the subscribed service, not your access to the evidence already delivered. The record’s history stays intact.

04

IP boundaries are explicit

Your raw data stays yours; we hold it as custodian, and export is available at any time. The evidence packs and per-home results we produce for you are licensed to you without restriction, to keep and use in your own systems. The governed record, the verdicts and the method behind them remain Aeterno property.

Independence

The record has no stake in what it shows.

We make no equipment, install nothing and fund no programmes. Every verdict on the record judges work we take no part in, and that standing is what makes your evidence worth something to the people it has to convince: the board, the funder, the tender, the resident.

Being paid by the people we assure is a fair challenge, so here is the answer. What a customer buys is never the verdict. The method is anchored to the national standard in force and is not negotiable per customer; verdicts are not negotiable either; a failing check stays visible until it is fixed. Independence here is a property of the method and the record, not a courtesy we extend.

It is also why no customer is named on this site: a record-keeper belongs to none of the parties it judges. References and deployment detail are shared in confidence as part of diligence.

Security

Security & compliance.

Split the way a security review splits it: what the platform runs on today, and what is configured with you at deployment. Every line here can be walked through live.

How the platform runs today.

Tenant isolation

Per-customer isolation with no data commingling between tenants

Journaled actions

Every outbound action needs an approval token and lands in an append-only journal

Audit trails

Action and access histories are recorded for review and export

Data encryption

Encryption at rest and in transit using industry-standard protocols

Configured with you at deployment.

Single sign-on

SSO against your identity provider over SAML 2.0 or OIDC, configured at deployment

Role-based access

RBAC with per-viewpoint permissions, so each team sees its own checked view of the record, mapped to your teams at deployment

Regional hosting

Hosting region and data-localisation requirements agreed per deployment

Where the evidence supports compliance.

MCS

Evidence outputs can support commissioning and installation-quality reviews against the requirements of MCS, the UK's installer certification scheme

Building regulations

Evidence packs can support building regulations compliance workflows

GDPR

Data processing agreements, privacy by design and data subject rights

Due diligence

Documentation supporting customer security review is available on request.

Before procurement asks

Frequently asked questions.

Next step

Review governance, ownership, or deployment fit.

We can walk through how trust, evidence and control work across your products, teams and deployment requirements.