Trust & Security
NEXUS AI is not a reskinned chatbot: it is an enterprise operating system whose moat is provable governance. Here is exactly what we do — and what we do not (yet) claim to do.
Verifiable work, not promises
Every agent action produces a chained SHA-256 cryptographic certificate (plan → execution → result → evaluation → signature). The chain is tamper-proof: altering one certificate breaks the signature of the following ones. Anyone — auditor, buyer, regulator — can verify it publicly, with no internal access.
Try public verificationData Vault — 7 layers
Defense in depth. Every status is stated honestly.
Encryption
AES-256 at rest, TLS 1.3 in transit (Supabase Vault).
Data minimization
The LLM receives data sanitized by level (PII masked / metadata / air-gap) via data-minimizer.
RLS isolation
Row-Level Security on every table, keyed on org_id. Strict multi-tenant isolation.
Audit trail
Append-only logs + tamper-proof certificate chain (chained SHA-256).
Key rotation
JWT rotation (1h) + API keys (90d).
Emergency stop button
Freeze all agents in under 5s (Owner) — /api/emergency/shutdown.
Air Gap
Docker/K8s deployment on the client's infrastructure, zero outbound data.
Governance
Verifiable work
Every action produces a chained SHA-256 certificate, publicly verifiable on /verify — the antithesis of agent-washing.
Company Constitution
Versioned governance rules, applied at every step of the agent execution cycle.
Policy Engine
Every tool call is checked against company policies BEFORE execution; otherwise it escalates.
Explainable Trust Score
A 0–100 autonomy score, decomposed and auditable, anchored in the certificate chain — never a black box.
Runtime guardrails
Prompt-injection / jailbreak detection on all untrusted input (visitors, RAG, SDK).
Compliance roadmap
Full transparency: we never claim a certification we have not obtained. "Aligned" means our architecture is mapped to the framework, without an independent audit.
| Framework | Status | Where we stand |
|---|---|---|
| SOC 2 Type II | In progress | Technical controls in place (encryption, RLS, audit, rotation). Independent audit to be scheduled. |
| ISO/IEC 27001 | Planned | ISMS to be formalized; the underlying technical controls are already deployed. |
| ISO/IEC 42001 (AI) | Planned | AI management system — governance (Constitution, Trust Score, Verifiable Work) lays the foundations. |
| EU AI Act | Aligned (not audited) | Traceability, transparency and tamper-proof logs mapped to the requirements; risk classification by use case. |
| NIST AI RMF | Aligned (not audited) | Govern/Map/Measure/Manage functions covered by the Constitution, Policy Engine and Trust Score. |
| Law 25 (Quebec) / PIPEDA | Aligned (not audited) | Data minimization, Canadian residency targeted, right to erasure via RLS + purge. |
| Data protection (Africa) | Aligned (not audited) | NDPA (Nigeria), DPA (Kenya), APDP (Benin), POPIA, etc.: per-tenant residency (af-south-1 / OVH Casablanca), African PII minimization, consent — Sovereignty Pact A1. |
A security question or a vendor questionnaire?
Our governance architecture is built to pass enterprise procurement reviews. Let’s talk.
Get started