Trust as a Criterion: Rethinking how Facilities Evaluate Autonomous Robots

Trust as a Criterion: Rethinking how Facilities Evaluate Autonomous Robots.
Not long ago, buying an autonomous cleaning robot was a straight forward operations decision.
How much would it lift productivity? How much labor cost would it take out? And how fast would it pay for itself? If the ROI cleared the hurdle, the deal moved forward.
Today, the buying process looks very different. IT wants to understand what it connects to. Compliance wants to know what data it records and where that ends up. Neither of them chose the machine, and neither of them is calculating the cost of cleaning to evaluate it.
Most operations leaders were never trained to evaluate that. Here is what to evaluate, and why camera-free, secure automation reduces operational risk, regardless of what regulations do next.
Why the criteria changed
The shift is easy to explain and has little to do with a single headline or regulation. It reflects a broader change in how companies evaluate connected technology.
Recent discussions and FCC actions around connected technologies, cybersecurity, data sovereignty and supply chain resilience have increased scrutiny of technology vendors across industries. Whether it's cloud software, telecommunications infrastructure or robotics, buyers are asking more questions about where technology comes from, how it is governed and who ultimately has access to it. At the same time, the nature of automation itself has changed.
- Automation went from pilot to production. Robots are no longer confined to a corner of the distribution center. They operate across warehouses, manufacturing lines and distribution centers, in and around people, inventory and proprietary processes.
- Robots became perceptive. To navigate reliably, a machine has to build and maintain a model of the environment in which it runs. That model is a description of your facility, and depending on the sensors – or cameras – involved, it can be a very detailed one.
- Connected became the default. Fleet management, remote monitoring, over-the-air updates and integration with warehouse systems are now expected features, and every connection is also a consideration.
- Facility layout stopped being trivial. Rack configuration, staging areas, line arrangement, pallet flow, changeover patterns: these are the physical expression of how a company competes. Contract manufacturers are often contractually barred from letting one client see another’s operation. Automotive plans stage tooling for products that have not been announced. Third-party logistics providers run competing brands under one roof.
None of that is new to an operations leader. What is new is that machines moving through these environments are no longer just machines. They are connected, software-driven systems that have become part of the broader technology ecosystem of the business.
Four areas every automation buyer should evaluate
- Data and Privacy. What the machine records, and what it keeps.
Every sensor is a data-collection decision, either by you or its vendor. It is important to understand what is captured, why it is captured, how long it is retained, and who can retrieve it afterwards. Two robots can do the same job while producing very different records for your facility. A machine that navigates by camera generates watchable imagery: layouts, inventory movement, production lines, and the people working around them. A machine that navigates by LiDAR builds spatial geometry, enough to move safely and precisely. That distinction decides whether your facility has to be governed as a video environment or never become one.
- Security and Connectivity. How the machine joins your network and systems.
Integration is where security either holds or leaks. Proprietary, undocumented connections are the ones that get built badly, maintained by nobody, and forgotten. Standard-based interfaces are inspectable by your own team. Ask whether the vendor offers a documented REST API, whether it supports an open fleet interoperability standard such as VDA 5050, and what a WMS integration actually exchanges. Cleaning coordination rarely needs inventory data. It usually needs to know whether an aisle is clear or a shift has ended. The right integration passes the minimum required to do the job and nothing more, and your team should be able to see exactly what that is.
- Governance and Control. Where the data lives, and whose law applies to it.
"In the cloud" is not a complete answer. Ask which cloud, in which jurisdiction, under which privacy regime, and critically, what actually has to leave your building for the robot to do its job. Control and operations data that never leaves your local network is fundamentally lower risk than data that must travel to function.
- Resilience and Vendor Trust. Who can update the machine, and who will still be there in seven years.
Two questions that are usually asked separately and belong together, because bothare really about dependency.
- Control: how are software updates signed and validated, can you stage them before a fleet-wide rollout, and who inside the vendor organization can push code to a machine standing inside your building? Over-the-air updates are a genuine benefit and a genuine attack surface.
- Continuity: where are spare parts held, what is the realistic lead time to your site, is service performed by the vendor’s own people or three subcontractors deep, and is this platform likely to be supported in seven years? A robot you cannot get parts for is a very expensive obstacle in an aisle.
If a vendor cannot answer these clearly, that is itself an answer.
What “trusted automation” looks like in practice
The encouraging part of this shift is that good answers already exist. Trusted automation shouldn’t compromise capability; it is capability engineered with these questions in mind from the start. Here is what a good answer looks like in each area.
- Data and Privacy.
A good answer starts with what is not collected. The strongest position on facility data is not a well-managed archive of it; it is not having generated it in the first place. Look for navigation that produces spatial geometry rather than watchable imagery, a sensor set kept deliberately small, a documented retention period, and a named jurisdiction with a named privacy regime for whatever isstored
In practice: KEMARO’s autonomous industrial sweepers navigate using LiDAR and 3D sensors rather than capturing video footage of the facilities they work in. The practical consequence is significant: robots clean large industrial floors autonomously, without creating visual records of warehouse layouts, inventory movements, production lines or the people around them. This is the core of the LiDAR-versus-camera question. LiDAR builds the spatial map a robot needs to move safely and precisely, but it does not produce a watchable picture of your operation. For facilities where processes are proprietary and workforce privacy is taken seriously, that distinction removes a real source of risk before it can ever materialize.
- Security and Connectivity.
The control path - the instructions that make the machine move – should belong on your own network, behind your own firewall rules, on a segment your OT team already governs. The cloud is for what genuinely benefits from being there: monitoring, reporting, updates. The test is simple: if the connection drops, does the machine keep doing its job?
In practice: Integration is where trust is often won or lost, so architecture matters. KEMARO robots can be connected to a warehouse control or management system through a standards-based REST API, but the command path runs across the customer's ownlocal network, behind their firewall rules. The system that issues instructions talks to the robot directly, on-site. Operational commands do not have to route through the cloud to work.
- Governance and control.
A good answer treats the machine as software that happens to have wheels. Updates signed and validated, stageable before fleet-wide rollout, with a small and identifiable set of people able to push code. Interfaces documented and standards-based, so your own team can inspect what is exchanged instead of taking it on trust. Integrations that pass the minimum required for the task. Transparency is doing the real work in this category: a vendor that publishes its interface is a vendor prepared to be checked.
In practice: KEMARO integrates through a documented REST API, supports VDA 5050 for fleet interoperability where robots share a floor with AGVs, and delivers software updates over the air through Sphere. What a cleaning integration exchanges stays close to what cleaning coordination actually needs: floor and shift status, not inventory.
- Vendor trust and resilience.
A good answer is a clear one: engineering and assembly you can locate on a map, spare parts held near the fleet with a lead time measured in days, service performed by people the vendor employs, and a commitment to the platform that outlasts the depreciation schedule. This is the part of the evaluation that never appears in a security questionnaire and determines more of the outcome than most of what does.
In practice: KEMARO pairs Swiss engineering and in-house assembly with a growing US organization: spare-parts availability and an expanding American service and support footprint anchored in Columbia, South Carolina, with an Atlanta office joining this year.
The point is not a single feature. It is that each of the buyer's questions has a deliberate, defensible answer, because the product was designed around them rather than retrofitted to them. This is what KEMARO calls privacy-by-design.
Why this matters regardless of what regulations do
It would be easy to frame all of this as a response to a changing regulatory climate. That framing overlooks the broader shift we're seeing in how automation is evaluated.
Regulations will keep evolving in every market. But the underlying reasons to prefer trusted automation do not depend on any specific rule. Not collecting data you do not need reduces risk today. Keeping control of data on your own network reduces the likelihood of a cyber-attack today. Choosing a vendor with local support and a stable supply chain protects uptime today.
In other words, privacy-by-design and secure integration are not compliance costs. They are operational risk reduction that also keep you on the right side of whereve rthe rules land next.
So, if you are evaluating automation right now, keep asking about productivity, labor, and ROI - those numbers still decide whether automation makes sense. But add one more question, and ask it early on: can we trust this technology inside our facility, and the company behind it, for years to come?
%20(1).jpg)




