Security and governance are the platform — not features bolted on top.
Nexoraa is engineered for regulated enterprises. Identity, data protection, AI assurance, and audit are first-class platform layers. This page summarises the controls; the Trust Center holds the artefacts.
How Nexoraa is governed.
Nexoraa applies governance across four domains: identity and access; data protection and residency; AI assurance; and operational governance. Each domain is enforced at the platform layer, not at the workflow layer — meaning every workflow that runs on Nexoraa inherits these controls by construction.
Identity and access.
SSO/SAML/OIDC
Enterprise identity provider integration. Azure AD, Okta, Google Workspace, and any SAML/OIDC-conformant provider. Local-only auth is not used in production.
MFA
MFA enforced on admin and privileged access; conditional access policies supported.
RBAC granularity
Fine-grained role-based access: prompt editor, agent deployer, admin, auditor, viewer, approver. Principle of least privilege enforced at every tool, dataset, and workspace.
Session management
Configurable timeout, invalidation, and concurrent session limits. No session fixation vulnerabilities.
Secrets management
API keys, DB credentials, LLM provider keys held in vault (HashiCorp Vault, AWS Secrets Manager, or equivalent). Automatic rotation. Never in code or config.
Data protection and residency.
Encryption at rest
AES-256 across databases, vector stores, file storage, and backups. Documented key rotation policy.
Encryption in transit
TLS 1.2 and above for all external and internal communication. Certificate management with auto-renewal.
PII detection and redaction
Automated scanning of prompts, responses, and logs for PII (Aadhaar, PAN, phone, email, etc.). Configurable redaction before logging.
Data classification
Public, internal, confidential, restricted — with handling rules per tier, including for RAG documents.
Data residency
Per-region deployment; LLM endpoints region-locked; control over where data is stored and processed.
Retention and deletion
Configurable retention per data class. Automated purge. Right-to-be-forgotten supported.
AI enforcement, Haluvance.
Signed contracts
A human-approved, signed contract defines exactly what each agent may do. No contract, no permission.
Single enforcement gateway
Every sensitive action passes through one boundary that holds all credentials — agents have no way around it.
Decision before action
Each action is checked against the contract before any tool runs, and returns allow, deny, or needs-approval.
Prompt injection protection
Guardrails against injection, jailbreak, and adversarial inputs — an agent still cannot exceed its contract.
Human sign-off
The most sensitive actions require an approver, verified and recorded before the action can resume.
Tamper-proof proof
Every decision is written to an append-only ledger before the action runs — evidence that survives audit.
Operational governance.
Audit logging
All authentication, permission changes, data access, and admin actions logged with tamper-evident storage. Retention per compliance.
Workflow lineage
Every workflow run carries a complete trace: inputs, retrieved sources, agent steps, validation outcomes, approvals.
Approval workflows
Human-in-the-loop approvals required for any action above policy threshold. Four-eyes principle supported.
Change management
Prompt, agent, and policy changes are versioned and require approval before promotion. Rollback is immediate.
Configuration drift
Production configuration is reconciled against source-of-truth in Git. Drift triggers alerts.
Incident management
Defined severity levels, escalation, and integrations with PagerDuty / ServiceNow. Documented runbooks for high-severity events.
Compliance posture.
Nexoraa's compliance program is structured to support enterprise procurement. Certifications and alignments are listed below; current status is maintained in the Trust Center.
SOC 2 Type II
On the platform's audit roadmap. Controls aligned to SOC 2 trust criteria (security, availability, processing integrity, confidentiality, privacy).
ISO 27001
Information security management system aligned to ISO 27001 controls.
HIPAA
HIPAA-ready deployment posture; BAA available for healthcare engagements.
GDPR / DPDP Act
Aligned to data subject rights, consent management, and privacy impact assessment requirements under GDPR (EU/UK) and India's DPDP Act.
AI Act / Responsible AI
Aligned to emerging AI regulation; risk assessment, bias monitoring, and explainability documented per workflow.
Customer compliance frameworks
Industry frameworks (IATF, AS9100, GxP, NERC CIP, RBI / SEBI guidelines, etc.) supported as governance configurations.
Vulnerability and threat management.
Vulnerability management is continuous. Static and dynamic application security testing run in CI; container images and dependencies are scanned on every build; third-party penetration testing runs at minimum annually with documented remediation.
Responsible AI by design.
Nexoraa is built on the principle that AI in regulated operations must be evidenced, sourced, validated, and reviewable. Confidence is not a feature; assurance is the platform.
Responsible AI is operationalised through Haluvance, through human-in-the-loop governance, and through contract-based enforcement. Workflow-level risk assessments are produced and retained; bias and drift monitoring are continuous; explainability is grounded in cited sources, not in narrative reconstruction.
Vendor and contract posture.
SLA
Contractual uptime, response time, and severity-aligned remediation commitments.
Source code escrow
Available for enterprise customers requiring continuity assurance.
Exit and portability
Documented exit process. All data, prompts, agent definitions, and embeddings are exportable. No lock-in.
IP ownership
Custom agents, prompts, workflows, and customer data remain customer property.
Indemnification
Indemnification against IP infringement claims and platform-defect-driven data breaches.
Sub-processor disclosure
Sub-processors disclosed and updated on the Trust Center.
