Your process data is the asset. It stays on our own infrastructure, it never trains a model anyone else uses, and it leaves permanently when you ask.
The aerospace and defence deployment ran in a regulated environment on the run/stop event log alone.
How many micro-stops, how long they lasted, and whether they came in bursts or evenly spread. Counts and durations.
No named operator data. Nothing that identifies who was on the line when a stop happened.
Your GDPR scope is unchanged by the deployment. There is no new category of personal data to declare.
Both are consequences of how the models are built, so they cannot drift out of compliance later.
Every score is produced from information available at that moment and no later. That is what makes offline validation meaningful, and it also means a score can never be explained by data the line did not yet have.
Scoring is one lightweight computation per machine every ten minutes. There is no GPU and no call to an external service, so there is no third party in the data path to audit.
How results are tested before they reach you is on How we validate.
If your team has a security review process, start it at the first conversation rather than after. Tell us what you need and we will work through it.