Trust Center

Documentation, certifications, and assurance artefacts.

Everything procurement, security, and compliance teams need to evaluate Nexoraa as a vendor — collected here. Some artefacts are public; others require a login or NDA.

Compliance Posture

Compliance posture.

Until each certification is achieved or attestation issued, the page uses clear status language and does not claim certifications that have not been issued.

SOC 2 Type II

Status to be populated — In progress / Achieved.

ISO 27001

Status to be populated.

ISO 27701

Status to be populated for privacy.

GDPR

Operating posture aligned; DPA available.

DPDP (India)

Operating posture aligned.

HIPAA

Operating posture aligned for healthcare deployments; BAA available.

PCI DSS

Where applicable, status to be populated.

Cloud-provider attestations

Inherited where applicable; documented per deployment model.

Documents Available

Documents available.

Security whitepaper

Public — describes platform security architecture and controls.

View Document

Architecture brief

Public — high-level architecture and deployment models.

Privacy policy

Public — at /legal/privacy.

DPA

Available on request — used in EU and UK contracts.

BAA

Available for healthcare contracts under HIPAA.

Standard contractual clauses

Available for cross-border data transfers.

Sub-processor list

Public — maintained in the Trust Center.

Penetration test summary

Available under NDA — request through account team.

Operational Practices

Operational practices.

Background checks

Performed for personnel with production access.

Access reviews

Quarterly minimum for production systems.

Change management

Formal change control for production releases.

Incident response

24/7 on-call for severity-1. Customer notification SLAs defined per contract.

Business continuity

Documented BCP. Tested DR. RPO and RTO targets per tier.

Sub-processor changes

Notified at least 30 days before introduction; opt-out paths defined.

Data Handling

Data handling.

Data residency

Configurable per deployment. Data does not leave the configured region for storage or processing.

Data isolation

Tenant-level isolation across data, queries, logs, and execution.

Data retention

Configurable per workspace and per data class. Customer-defined retention supported.

Data deletion

Right-to-be-forgotten supported with automated purge of source artefacts, embeddings, and logs.

Backups

Encrypted, region-bound, retained per policy.

Vulnerability Disclosure

Vulnerability disclosure.

Nexoraa welcomes coordinated security disclosure. Researchers can report findings through the channel below.

Reporting channel

security@nexoraa.com, or the address designated at launch.

Acknowledgement target

Within 2 business days.

Triage target

Within 5 business days for valid reports.

Safe harbour

Good-faith research that complies with our disclosure policy is not pursued legally.

Next Step

Request the documentation your review needs.