Oversight for your fleet. Custody for your projects.
A layer above the fleet, not a layer in charge of it
Oversee, aggregate, improve, distribute


A fleet gets smarter from its own operation
A cloud that holds your projects and cannot read them
Where this stands today
In buildThe guarantee above is a decided design and part of Cloud’s first release scope — not an open door yet. Studio’s working backup destinations today are your own disk, Files, and an iCloud Drive location you choose; the Cloud destination and the relay below are the parts being built. The encryption model is not new work invented for a cloud feature: it is the same passphrase-sealed archive Studio already writes for those local destinations, which is exactly why the guarantee can be stated this precisely.
What zero-knowledge costs you
Lose the passphrase and the archive is unrecoverable — by design, and Cloud cannot help. There is no backdoor, no support-side reset, and nothing held in escrow, because every one of those would mean Cloud could read your project. That trade is what the guarantee is made of, and it is the correct one for work like facility topology, control architecture, and supplier data.
Transport between your devices. Nothing more.
A bundle is one way work moves — not the only one
Every Studio platform authors a real project on its own, phones included — a capture bundle is not the price of working on a small screen. It is for the case where the capture and the consolidation genuinely happen on different devices, and Cloud’s whole role in it is to hold the sealed package in between.
One substrate, opposite postures toward your content
| Fleet aggregation | Studio custody | |
|---|---|---|
| Who the client is | Your edge servers, unattended, on their own device credentials. | Studio, on your own devices, signed in as you. |
| What Cloud holds | Runs and measurements the edges report, plus process-class template and model definitions and their identity. | Client-encrypted whole-project snapshots and encrypted capture bundles — opaque blobs and a thin metadata record. |
| What Cloud can read | All of it. Content-aware by design — aggregation is impossible otherwise. | None of it. Content-opaque by design — Cloud holds no key and cannot decrypt. |
| What it does with it | Groups like-processes, compares runs across edges, and in the later phase refines models from that data. | Stores, lists, and hands back the same bytes. It never inspects, merges, or reconciles. |
| What it is authoritative for | Template and model definitions, and their identity. Never adoption, never execution — that is the edge’s. | Nothing. Your device holds the authoritative project; Cloud is a copy you may keep. |
Same account, same sign-in, same storage underneath — two different clients with opposite content postures. Aggregation has to understand what it holds; custody must not be able to.
What’s available now, what’s being built, and what’s next
- Fleet registry & oversight
- Run / measurement ingestion
- Process-class template registry + identity
- Time-series query + cross-run comparison
- Zero-knowledge project backup as a Cloud destination
- Encrypted capture-bundle relay (store-and-forward)
- Plan-bound storage quota and snapshot retention
- Physics + inference model registry and lineage
- Model / template distribution & adoption back to the fleet
- Cloud-side composition of refined templates
- Cloud-run training / physics calibration
Cloud observes. The edge decides. Studio owns the design.
- Oversee your fleet — which edges exist, their status, version, and active runs
- Group like-processes across edges into comparable sets, and compare them
- Issue and hold process-class template and model definitions, and their identity
- Store client-encrypted Studio project snapshots it has no key for
- Relay encrypted capture bundles between your own devices, then drop them
- Not a runtime and not a control plane — it never starts, stops, or mutates a run
- Not required — an edge runs, and Studio authors, with no cloud in the path
- Not the system of record for a Studio project, and never a merge authority
- Not able to read what it holds for Studio — no key, no decryption, no inspection
- No cross-tenant sharing — a fleet learns only from its own operation
- Not a SCADA or DCS replacement, and not an industrial historian