Security and data protection, in plain language.
This page is written to be sent to your DPO. Every claim on it is verifiable in the product.
- You choose where your data lives: Frankfurt, London or Virginia.
- Your documents never train a model. It isn't a toggle you could miss — the setting reads "Never" and cannot be changed.
- The audit log is append-only. Not even an owner can edit or delete an entry.
- Erasure takes effect within 30 days — including in backups.
Data regions
Documents, embeddings and logs are stored and processed in the region your organisation selects. Changing region moves existing documents and their embeddings, and the transfer is recorded in the audit log.
Training stance
Your documents are never used to train any model, by us or by a provider. This is not a setting you could misconfigure — in the product it reads "Never" and cannot be changed.
PII redaction
Names, email addresses and account numbers are replaced with placeholders before text is sent to a provider.
Redaction runs before the request leaves this server, so a masked name is never transmitted. It cannot catch everything — treat it as a reduction in exposure, not a guarantee.
Retention and erasure
Retention is configurable per organisation, for documents and conversations separately — from 90 days to indefinite. Deleting a conversation also deletes its Sheets.
An export is a machine-readable copy of every document, conversation and Sheet in this workspace. Erasure is permanent and takes effect within 30 days, including in backups.
Audit log
Entries cannot be edited or deleted, including by an owner. Retained for the life of the workspace and included in an export.
Each question, retrieval and export is written to the audit log, not only administrative changes.
Provider posture
Your organisation chooses which AI providers may process its content, and the picker prints each provider's cautions at the same weight as its strengths. Administrators can restrict the picker to providers hosted in your data region.
Sub-processors
The AI providers listed above act as processors only for the conversations you route to them, and only when your organisation selects them.
Hosting is provided in your selected data region (Frankfurt, London or Virginia). A complete, current sub-processor register is available on request.
Access control
Four roles — owner, admin, member and viewer. SSO over SAML or OIDC, enforceable so password sign-in is refused once it is on. SCIM directory sync, so members are created and deactivated by your directory rather than by hand.
API keys
Coming soonOnly the prefix and a hash are stored. Revoking a key takes effect immediately for every request in flight.
The public API at api.nerix.ai is not yet live; keys and scopes are managed in the product today, ahead of it.
Application security
A strict per-request-nonce Content-Security-Policy is live on every page. No third-party scripts, fonts, trackers or CDNs anywhere on nerix.ai — everything is self-hosted. Sharing a conversation redacts it by default, and API secrets are stored as a prefix and a hash, so they cannot be read back.
No badges we haven't earned.
nerix.ai does not yet hold SOC 2 or ISO 27001. What we can show you today: the append-only audit log, the fixed no-training stance, region-pinned storage, GDPR export and erasure, and this page. When a certification lands, it will be listed here with its scope.