Where the work runs
Projects and chat stay on your PC either way. The difference is where the model runs, and whether an AI request reaches us.
| Cloud subscription | Perpetual, on-prem | |
|---|---|---|
| Projects and chat | On your PC | On your PC |
| AI inference | Our infrastructure, per request | Your model, inside your network |
| Sent to PLC Copilot | Context for that request, credit metering, and health signals | No AI request data |
Not used for training
We do not use your PLC logic, project files, prompts, chat history, or outputs to train PLC Copilot or third-party models. Our agreements with AI providers prohibit that use.
- No training on customer engineering data
- Prompts, chat, and outputs included
- Provider agreements prohibit that use
The project stays on the machine
The workspace lives in the desktop app. We do not keep your programs and attachments files in cloud.
- Projects and workspace stored locally
- Chat history stored locally
- Attachments will be read locally
What a request includes
Each request goes out over an encrypted, authenticated connection. It carries the context for that answer, not your whole program.
- Context for that answer, not the full project
- Account and usage data to meter credits
- Separate health signals, not your logic archive
- Kept only as long as those jobs require
When nothing can leave your network
A perpetual license runs the app on your machines and calls your model provider, on your network or air-gapped. Licensing is on Subscription vs perpetual. If you stay on subscription and want the health and diagnostic signals in section 03 turned off, a zero-data retention agreement does that in writing.
- No AI request sent to PLC Copilot
- Internal network or air-gapped
- Zero-data retention
Encryption and access
Traffic to PLC Copilot is encrypted, and access inside Forge IO is limited to the people who need it to run the service.
- TLS in transit
- Encryption at rest on our infrastructure
- Role-based access
- No access to your corporate or OT network
Compliance
SOC 2 Type II and ISO 27001 audits are underway with an independent agency.
- DPA covers GDPR and US state privacy laws
- Data we process is handled in the United States by default
- EU processing available in an enterprise agreement

