Enterprise manufacturing platform — Go live in 60 days. Schedule an executive briefing.Book a demo
FOSFactoryOperating System

Trust

Security & Compliance

How FOS protects manufacturing data — encryption, access controls, audit trails, and independent assurance aligned to SOC 2 and ISO 27001.

Factory Operating System · Pune, India

Manufacturing ERP holds your orders, costs, drawings metadata, and employee records. FOS is designed with defense in depth so plant data stays confidential, available, and traceable.

Infrastructure

  • Hosted on ISO 27001-certified cloud providers with regional data residency options for India.
  • Encryption in transit (TLS 1.2+) and at rest (AES-256) for databases and backups.
  • Network segmentation, WAF, DDoS mitigation, and continuous vulnerability monitoring.

Application security

  • Role-based access control, least-privilege defaults, and optional SSO/SAML for enterprise.
  • Immutable audit logs for financial and master-data changes.
  • Secure SDLC: code review, dependency scanning, and periodic penetration testing.

Assurance

SOC 2 Type IIControls audited annually for security, availability, and confidentiality.
ISO 27001Information security management aligned to international standards.
GDPR readyData processing terms, subprocessors list, and subject rights workflows.

Business continuity

Automated backups, point-in-time recovery, and a 99.9% uptime SLA on enterprise plans. Incident response runbooks include customer notification within contractual timelines.

Report a concern

Email security@fos-erp.com for vulnerability reports or security questionnaires.

Last reviewed: July 2026

Frequently asked questions.

Top questions about FOS ERP security — answered for manufacturers in India.

How does FOS protect manufacturing data at rest?

FOS encrypts databases and backups at rest using AES-256 on ISO 27001-certified cloud infrastructure. Indian data residency options are available. Automated backups and point-in-time recovery support business continuity for orders, costs, drawings metadata, and employee records stored in the platform.

What encryption does FOS ERP use in transit?

All traffic between browsers, APIs, and FOS services uses TLS 1.2 or higher. Network segmentation, web application firewalls, and DDoS mitigation protect production endpoints. Shop-floor tablets and remote planners connect over encrypted channels without separate VPN requirements for standard cloud access.

Does FOS support role-based access control?

Yes. FOS provides role-based access control with least-privilege defaults for planners, operators, stores, purchase, quality, and finance. Administrators define which plants, modules, and transactions each user sees. Optional SSO and SAML integrate with enterprise identity providers for multi-plant manufacturers.

What audit trails does FOS ERP provide?

FOS maintains immutable audit logs for financial postings, master-data changes, and critical operational events. Quality holds, dispatch approvals, and inventory adjustments are traceable for internal audits and customer compliance. Logs support investigations without relying on informal shop-floor records.

Is FOS ERP SOC 2 Type II certified?

FOS maintains SOC 2 Type II alignment with controls audited annually for security, availability, and confidentiality. Manufacturing customers use SOC reports during vendor assessments. ISO 27001 practices and GDPR-ready data handling complement SOC assurance for plants evaluating cloud ERP risk.

Does FOS offer SSO for enterprise customers?

Yes. Enterprise deployments support SSO and SAML integration with corporate identity providers. Centralized authentication simplifies user lifecycle management across multiple plants and hundreds of shop-floor and office users without shared passwords or manual deprovisioning delays.

What uptime SLA does FOS provide?

FOS offers a 99.9% uptime SLA on enterprise plans with monitored infrastructure and incident response runbooks. Scheduled maintenance is communicated in advance. Business continuity includes automated backups and recovery procedures so production and finance teams maintain access during disruptions.

How does FOS handle incident response?

FOS maintains incident response runbooks including customer notification within contractual timelines. Security events are triaged by a dedicated team. Vulnerability monitoring, dependency scanning, and periodic penetration testing reduce exposure. Status updates follow agreed communication channels for affected manufacturing accounts.

Where can I report a security vulnerability?

Email security@fos-erp.com to report vulnerabilities or request security questionnaires. FOS reviews responsible disclosure reports and responds per our security policy. Enterprise prospects evaluating FOS for plant data can request SOC reports, architecture summaries, and subprocessors documentation.

Does FOS perform penetration testing?

Yes. FOS follows a secure SDLC with code review, dependency scanning, and periodic penetration testing on the platform. Controls align with SOC 2 Type II and ISO 27001 practices. Manufacturing customers benefit from continuous vulnerability monitoring on cloud-hosted ERP infrastructure.

Executive briefing

Ready to standardize operations?

See FOS mapped to your industry and modules in a focused 30-minute session — no obligation, no generic pitch deck.

  • Live in ~6 weeks
  • Industry-specific scope
  • Response in 1 business day