Platform · Security and Governance

Security and governance are the platform — not features bolted on top.

Nexoraa is engineered for regulated enterprises. Identity, data protection, AI assurance, and audit are first-class platform layers. This page summarises the controls; the Trust Center holds the artefacts.

Governance

How Nexoraa is governed.

Nexoraa applies governance across four domains: identity and access; data protection and residency; AI assurance; and operational governance. Each domain is enforced at the platform layer, not at the workflow layer — meaning every workflow that runs on Nexoraa inherits these controls by construction.

Identity and Access

Identity and access.

SSO/SAML/OIDC

Enterprise identity provider integration. Azure AD, Okta, Google Workspace, and any SAML/OIDC-conformant provider. Local-only auth is not used in production.

MFA

MFA enforced on admin and privileged access; conditional access policies supported.

RBAC granularity

Fine-grained role-based access: prompt editor, agent deployer, admin, auditor, viewer, approver. Principle of least privilege enforced at every tool, dataset, and workspace.

Session management

Configurable timeout, invalidation, and concurrent session limits. No session fixation vulnerabilities.

Secrets management

API keys, DB credentials, LLM provider keys held in vault (HashiCorp Vault, AWS Secrets Manager, or equivalent). Automatic rotation. Never in code or config.

Data Protection

Data protection and residency.

Encryption at rest

AES-256 across databases, vector stores, file storage, and backups. Documented key rotation policy.

Encryption in transit

TLS 1.2 and above for all external and internal communication. Certificate management with auto-renewal.

PII detection and redaction

Automated scanning of prompts, responses, and logs for PII (Aadhaar, PAN, phone, email, etc.). Configurable redaction before logging.

Data classification

Public, internal, confidential, restricted — with handling rules per tier, including for RAG documents.

Data residency

Per-region deployment; LLM endpoints region-locked; control over where data is stored and processed.

Retention and deletion

Configurable retention per data class. Automated purge. Right-to-be-forgotten supported.

AI Enforcement

AI enforcement, Haluvance.

Signed contracts

A human-approved, signed contract defines exactly what each agent may do. No contract, no permission.

Single enforcement gateway

Every sensitive action passes through one boundary that holds all credentials — agents have no way around it.

Decision before action

Each action is checked against the contract before any tool runs, and returns allow, deny, or needs-approval.

Prompt injection protection

Guardrails against injection, jailbreak, and adversarial inputs — an agent still cannot exceed its contract.

Human sign-off

The most sensitive actions require an approver, verified and recorded before the action can resume.

Tamper-proof proof

Every decision is written to an append-only ledger before the action runs — evidence that survives audit.

Operational Governance

Operational governance.

Audit logging

All authentication, permission changes, data access, and admin actions logged with tamper-evident storage. Retention per compliance.

Workflow lineage

Every workflow run carries a complete trace: inputs, retrieved sources, agent steps, validation outcomes, approvals.

Approval workflows

Human-in-the-loop approvals required for any action above policy threshold. Four-eyes principle supported.

Change management

Prompt, agent, and policy changes are versioned and require approval before promotion. Rollback is immediate.

Configuration drift

Production configuration is reconciled against source-of-truth in Git. Drift triggers alerts.

Incident management

Defined severity levels, escalation, and integrations with PagerDuty / ServiceNow. Documented runbooks for high-severity events.

Compliance Posture

Compliance posture.

Nexoraa's compliance program is structured to support enterprise procurement. Certifications and alignments are listed below; current status is maintained in the Trust Center.

SOC 2 Type II

On the platform's audit roadmap. Controls aligned to SOC 2 trust criteria (security, availability, processing integrity, confidentiality, privacy).

ISO 27001

Information security management system aligned to ISO 27001 controls.

HIPAA

HIPAA-ready deployment posture; BAA available for healthcare engagements.

GDPR / DPDP Act

Aligned to data subject rights, consent management, and privacy impact assessment requirements under GDPR (EU/UK) and India's DPDP Act.

AI Act / Responsible AI

Aligned to emerging AI regulation; risk assessment, bias monitoring, and explainability documented per workflow.

Customer compliance frameworks

Industry frameworks (IATF, AS9100, GxP, NERC CIP, RBI / SEBI guidelines, etc.) supported as governance configurations.

Threat Management

Vulnerability and threat management.

Vulnerability management is continuous. Static and dynamic application security testing run in CI; container images and dependencies are scanned on every build; third-party penetration testing runs at minimum annually with documented remediation.

Responsible AI

Responsible AI by design.

Nexoraa is built on the principle that AI in regulated operations must be evidenced, sourced, validated, and reviewable. Confidence is not a feature; assurance is the platform.

Responsible AI is operationalised through Haluvance, through human-in-the-loop governance, and through contract-based enforcement. Workflow-level risk assessments are produced and retained; bias and drift monitoring are continuous; explainability is grounded in cited sources, not in narrative reconstruction.

Vendor Posture

Vendor and contract posture.

SLA

Contractual uptime, response time, and severity-aligned remediation commitments.

Source code escrow

Available for enterprise customers requiring continuity assurance.

Exit and portability

Documented exit process. All data, prompts, agent definitions, and embeddings are exportable. No lock-in.

IP ownership

Custom agents, prompts, workflows, and customer data remain customer property.

Indemnification

Indemnification against IP infringement claims and platform-defect-driven data breaches.

Sub-processor disclosure

Sub-processors disclosed and updated on the Trust Center.

Next Step

Bring your security questionnaire. We respond against existing controls, not against marketing copy.