Supplier Assurance

Procurement & Air-Gap FAQ

The questions a supplier assurance team asks before a safety tool is allowed onto a restricted network — answered plainly, so you can paste them straight into a questionnaire.

Book an Engineering Walkthrough Ask a specific question

Where does our data live?

On your machine or your network. Each project is a structured Excel workbook held in a data directory you choose; there is no SAFOPS-operated database and no hosted tenancy involved in an on-premise or air-gapped deployment. Hosted deployment is available if you want it, but it is an option rather than the architecture.

Does it phone home?

No telemetry, no analytics, no crash reporting, no licence check. The application contains no outbound calls of that kind at all.

Two features can make outbound connections, and both are off unless you configure them:

  • The AI copilot calls whichever model provider you point it at. It can be pointed at a model running on your own hardware, in which case nothing leaves your network. It can also simply be left disabled.
  • External audit anchoring is an optional tool that submits a hash of your audit log to an RFC 3161 timestamp authority, so a third party can attest that the record existed unmodified at a given time. It is run deliberately, never automatically, and can be pointed at an internal timestamp authority or not used at all.

A default air-gapped install makes no outbound connection whatsoever.

What are the prerequisites?

SAFOPS is a Python web application served locally or from a server you control, used through a standard browser. There is no database server to provision, no cloud account, and no per-workstation client install — users point a browser at it. It is not distributed as a single Windows executable; if your environment requires one, raise it during procurement and we will tell you plainly whether we can meet it rather than after contract.

How are updates handled on an air-gapped network?

As a versioned package transferred by whatever route your network already permits. Nothing in the application reaches out for updates, and no update service needs to be reachable for it to keep running. An instance that is never updated keeps working indefinitely.

Is there vendor lock-in?

Projects are ordinary .xlsx workbooks with documented sheets, readable in Excel without SAFOPS installed. The whole project exports to machine-readable JSON, reports to Word, PDF and HTML, and the interactive map downloads as a standalone HTML file. Import into SAFOPS from an existing hazard register or a legacy tool is handled by our engineers as part of migration rather than as a self-service upload — see bringing your existing data across.

What happens if SAFOPS ceases to trade?

Your hazard data, barriers, claims, evidence references and tamper-evident audit chain remain in an open workbook your engineers can read, edit and defend without us. What an open workbook cannot carry is the computation — the PFD/PFH ladders, the deterministic change-impact analysis, the residual frequency arithmetic. For programmes that need the engine guaranteed as well as the data, SAFOPS can be supplied under a source code escrow agreement with an established UK escrow agent. Ask for it during procurement.

Who has access, and can we prove what changed?

Named accounts with role-based permissions and optional two-factor authentication. Every edit is written into a SHA-256 hash chain, so the history is tamper-evident rather than merely recorded — you can demonstrate that a record has not been altered, not just assert it.

Perpetual by Design, Independent by Default

SAFOPS is licensed perpetually. Installed instances contain no external activation steps, runtime licence checks, or hardcoded expiries — operating indefinitely across air-gapped networks with zero outbound dependencies. Your tooling and data remain functional regardless of vendor status.

  • Licensing models: granted per programme or per facility (site-wide).
  • Optional maintenance: annual updates and technical support are available separately. Lapsing support stops new releases, never the running software.
  • Continuity assurance: formal source code escrow agreements available on request.

Pricing on application.

Engineered by Practitioners

SAFOPS is built, maintained, and supported by career safety engineers with decades of direct programme experience across the UK’s highest-hazard sectors — including defence, nuclear, rail, and aerospace.

We engineered the platform to solve the exact regulatory, audit, and traceability bottlenecks we spent our careers navigating. When you request support or book an engineering walkthrough, you engage directly with practising safety specialists who understand your regulatory regime.

Migration and authoring can also be delivered as a service — our SQEP engineers can move your legacy hazard logs across, populate the models, or write the safety case itself. See how the service works.

Something not covered here?

Supplier questionnaires in this sector run to forty pages and no FAQ anticipates all of it. Send us the questionnaire and you will get direct, specific answers from someone who understands what the question is actually testing — including an honest “no” where that is the answer. Get in touch.

Bring us your assurance questions early

It is cheaper for both of us to find a blocker now than after a pilot. We would rather tell you something is out of scope than discover it at contract.

Book an Engineering Walkthrough Security & Deployment