Security and governance
Phoeniks treats security controls as engineered platform capabilities rather than policy statements: role-based access, tenant isolation, immutable audit logging over data access and model runs, encryption in transit and at rest, and regional residency options.
- Role-based, tenant isolated
- Immutable over access, exports, model runs
- EU, Brazil, Thailand, India
- Shared across GDPR, LGPD, PDPA, DPDP
Controls#
- Role-based access control with tenant isolation between institutional clients.
- Immutable audit logging over data access, exports and model runs.
- Encryption in transit and at rest, with separated key management.
- Regional data residency options for EU, Brazilian, Thai and Indian data.
- Documented change management over model and pipeline releases.
- Incident response with defined notification paths.
Data-subject rights#
Access, rectification and erasure requests are handled through platform tooling shared across GDPR, LGPD, PDPA and DPDP obligations, so a request is executed consistently regardless of jurisdiction.
Frequently asked
- Is client data used to train models?
- No. Client-supplied data is isolated to that client's tenant and is not used to improve models for other clients unless a separate written agreement says otherwise.
Related pages
Methodology
The Phoeniks methodology: a process-based APSIM, DSSAT and ORYZA ensemble, scenario configuration, scoring engine and a reproducibility ledger.
Sources and licensing
Every source Phoeniks ingests, what it contributes, and how licence terms and provenance are enforced before a record is exposed commercially.
Validation and evidence
Holdout protocol, calibration, tail and covariance testing, evidence scoring levels and the reproducibility ledger behind every Phoeniks figure.
See also
Request access
Institutional access. No self-serve trial.