Security & governance

Controls designed in, not added afterwards.

Identity, data boundaries, action limits, and evaluation are part of the architecture from the first design review — retrofitting them is what stops most AI work from reaching production.

Control domains

  • Identity and permissions

    The requesting identity remains part of every retrieval and action decision.
    • SSO and role mapping
    • Source permission enforcement
    • Least-privilege service access
  • Data and privacy

    Data use, retention, residency, and deletion are designed for the customer context.
    • Purpose-bounded retrieval
    • Retention and deletion policy
    • Sensitive-data handling
  • Models and tools

    Models and tools receive only the context and authority required for the task.
    • Model routing policy
    • Tool allowlists and schemas
    • Prompt-injection defenses
  • Human control

    Consequential actions remain visible to an accountable business owner.
    • Risk-tiered approval
    • Edit, reject, and escalate
    • Named decision ownership
  • Operations and audit

    The system records enough evidence to investigate, recover, and improve.
    • Source and action traces
    • Safe retries and failure queues
    • Evaluation and incident review

No unverified certification claims.

Nexroza does not claim SOC 2, ISO 27001, HIPAA, PCI, or any other certification it does not hold. Where a control is designed rather than audited, it is described as designed.

Certification status will be stated here plainly once there is something to state.

Start with clarity

If the business case isn’t there, we’ll tell you before you build.