ambiwizeambiwize

Evidence is written once. After that, nobody alters it.

Anyone buying cold chain governance is right to ask hard questions. This page answers them, starting with the architectural decision that defines everything else.

01 — The question

What if someone corrects the record after the deviation?

It is the right question. A platform whose purpose is to produce regulatory proof is worthless if that proof can be adjusted after the fact, whether by the customer or by the vendor.

The answer is in how the system was built.

02 — The architecture

Append-only record. No exceptions.

Every reading, every custody transfer and every document enters the shipment record incrementally, with a timestamp and a source. A later correction does not replace the earlier data: it enters as a new event identifying who corrected it, when and why. The original record stays visible in the audit trail.

There is no path by which ambiwize, the logistics operator or the shipper can erase an event already written. The guarantee holds at the level of administrative database access.

Production data resides in-country by default, in the same region as the operation it serves — Brazilian data in Brazil, for example — meeting local data residency requirements without exception.

03 — AI under human control

ambiwize proposes. Quality decides. Always.

The AI layer assesses the evidence and proposes a verdict, with its reasoning exposed. It takes no autonomous decision on product disposition and acts on nobody's control system. The quality professional can accept, alter or override any proposal, and both the proposal and the decision are logged.

Customer data is not used to train or tune models. It is processed for that customer's operation and nothing else. When the customer requests deletion, the data is deleted.

04 — Controls

What is implemented today.

Encryption
TLS 1.2 or above on all web and API traffic. Data at rest and backups encrypted, with keys managed by the cloud provider and access logged.
Authentication
MFA mandatory on all administrative access, both for platform users and for the ambiwize team.
Isolation
Logical tenant separation, with role-based access control within each organisation.
Incident response
Documented procedure, named incident lead, and a contractual commitment to notify within 72 hours of becoming aware, per the DPA.
Subprocessors
Named list available. Contracted customers receive prior notice and a right to object to changes.
Retention
Retention periods set by contract. Complete deletion on request.

05 — Qualification

The questions a Quality Manager asks before go-live.

A Quality Manager who signs the sanitary licence carries personal professional liability for what leaves the warehouse. Those questions are not commercial, and none of them is answered by a presentation.

The ones we hear most often: sensor accuracy and measurement uncertainty; calibration certificates traceable to RBC/INMETRO and calibration frequency; computerised system validation (IQ/OQ/PQ); audit trail integrity and data integrity principles; the legal basis of the electronic signature; access control and change control; retention period, backup and disaster recovery.

We welcome every question on this list. Reach out and we will answer directly.

06 — The frameworks

The frameworks informed the design, not the other way round.

ANVISA RDC 430 / 653
The append-only record and custody attribution support demonstrating that storage conditions were maintained throughout distribution, and the risk assessment of variables not continuously monitored.
LGPD
Primary data protection framework. Designated DPO, documented legal basis per purpose, and support for data subject rights per the DPA. Production data in Brazil.
ISO/IEC 27001:2022
Primary certification track. Controls are implemented today and designed against the standard. The independent audit is not yet complete.
SOC 2
Secondary track, planned after ISO 27001. Type I first, Type II after the twelve-month observation window.
GDPR
For customers with international operations, the data protection programme aligns with GDPR principles as contractually agreed.

On certification

We prioritise architecture and transparency.

ISO/IEC 27001 is our primary track and SOC 2 follows. We do not publish timelines, as they depend on factors outside our control.

Our infrastructure runs on Google Cloud, whose certifications cover Google's infrastructure and do not constitute an independent audit of ambiwize.

Until formal certification is complete, we commit to operating in line with the controls described here, responding to security questionnaires under NDA, accepting reasonable customer audit per the DPA, and communicating any material change to active customers.

07 — Documentation and technical review

Procurement and information security teams require different levels of detail. We support both.

Available on request: the full Information Security Overview under NDA; vendor security questionnaires at the level of detail required; the DPA and named subprocessor list; and a technical architecture review with our team.

For data protection enquiries, contact our Data Protection Officer at dpo@ambiwize.com

Talk to the team

Ready to see the evidence in action?

Submit your questionnaire or tell us what your audit requires. We respond directly.