Documentation, certifications, and assurance artefacts.
Everything procurement, security, and compliance teams need to evaluate Nexoraa as a vendor — collected here. Some artefacts are public; others require a login or NDA.
Compliance posture.
Until each certification is achieved or attestation issued, the page uses clear status language and does not claim certifications that have not been issued.
SOC 2 Type II
Status to be populated — In progress / Achieved.
ISO 27001
Status to be populated.
ISO 27701
Status to be populated for privacy.
GDPR
Operating posture aligned; DPA available.
DPDP (India)
Operating posture aligned.
HIPAA
Operating posture aligned for healthcare deployments; BAA available.
PCI DSS
Where applicable, status to be populated.
Cloud-provider attestations
Inherited where applicable; documented per deployment model.
Documents available.
Architecture brief
Public — high-level architecture and deployment models.
Privacy policy
Public — at /legal/privacy.
DPA
Available on request — used in EU and UK contracts.
BAA
Available for healthcare contracts under HIPAA.
Standard contractual clauses
Available for cross-border data transfers.
Sub-processor list
Public — maintained in the Trust Center.
Penetration test summary
Available under NDA — request through account team.
Operational practices.
Background checks
Performed for personnel with production access.
Access reviews
Quarterly minimum for production systems.
Change management
Formal change control for production releases.
Incident response
24/7 on-call for severity-1. Customer notification SLAs defined per contract.
Business continuity
Documented BCP. Tested DR. RPO and RTO targets per tier.
Sub-processor changes
Notified at least 30 days before introduction; opt-out paths defined.
Data handling.
Data residency
Configurable per deployment. Data does not leave the configured region for storage or processing.
Data isolation
Tenant-level isolation across data, queries, logs, and execution.
Data retention
Configurable per workspace and per data class. Customer-defined retention supported.
Data deletion
Right-to-be-forgotten supported with automated purge of source artefacts, embeddings, and logs.
Backups
Encrypted, region-bound, retained per policy.
Vulnerability disclosure.
Nexoraa welcomes coordinated security disclosure. Researchers can report findings through the channel below.
Reporting channel
security@nexoraa.com, or the address designated at launch.
Acknowledgement target
Within 2 business days.
Triage target
Within 5 business days for valid reports.
Safe harbour
Good-faith research that complies with our disclosure policy is not pursued legally.
