Evidence is written once. After that, nobody alters it.
Anyone buying cold chain governance is right to ask hard questions. This page answers them, starting with the architectural decision that defines everything else.
01 — The question
What if someone corrects the record after the deviation?
It is the right question. A platform whose purpose is to produce regulatory proof is worthless if that proof can be adjusted after the fact, whether by the customer or by the vendor.
The answer is in how the system was built.
02 — The architecture
Append-only record. No exceptions.
Every reading, every custody transfer and every document enters the shipment record incrementally, with a timestamp and a source. A later correction does not replace the earlier data: it enters as a new event identifying who corrected it, when and why. The original record stays visible in the audit trail.
There is no path by which ambiwize, the logistics operator or the shipper can erase an event already written. The guarantee holds at the level of administrative database access.
Production data resides in-country by default, in the same region as the operation it serves — Brazilian data in Brazil, for example — meeting local data residency requirements without exception.
03 — AI under human control
ambiwize proposes. Quality decides. Always.
The AI layer assesses the evidence and proposes a verdict, with its reasoning exposed. It takes no autonomous decision on product disposition and acts on nobody's control system. The quality professional can accept, alter or override any proposal, and both the proposal and the decision are logged.
Customer data is not used to train or tune models. It is processed for that customer's operation and nothing else. When the customer requests deletion, the data is deleted.
04 — Controls
What is implemented today.
05 — Qualification
The questions a Quality Manager asks before go-live.
A Quality Manager who signs the sanitary licence carries personal professional liability for what leaves the warehouse. Those questions are not commercial, and none of them is answered by a presentation.
The ones we hear most often: sensor accuracy and measurement uncertainty; calibration certificates traceable to RBC/INMETRO and calibration frequency; computerised system validation (IQ/OQ/PQ); audit trail integrity and data integrity principles; the legal basis of the electronic signature; access control and change control; retention period, backup and disaster recovery.
We welcome every question on this list. Reach out and we will answer directly.
06 — The frameworks
The frameworks informed the design, not the other way round.
On certification
We prioritise architecture and transparency.
ISO/IEC 27001 is our primary track and SOC 2 follows. We do not publish timelines, as they depend on factors outside our control.
Our infrastructure runs on Google Cloud, whose certifications cover Google's infrastructure and do not constitute an independent audit of ambiwize.
Until formal certification is complete, we commit to operating in line with the controls described here, responding to security questionnaires under NDA, accepting reasonable customer audit per the DPA, and communicating any material change to active customers.
07 — Documentation and technical review
Procurement and information security teams require different levels of detail. We support both.
Available on request: the full Information Security Overview under NDA; vendor security questionnaires at the level of detail required; the DPA and named subprocessor list; and a technical architecture review with our team.
For data protection enquiries, contact our Data Protection Officer at dpo@ambiwize.com
Talk to the team
Ready to see the evidence in action?
Submit your questionnaire or tell us what your audit requires. We respond directly.

