Trust & Security

NEXUS AI is not a reskinned chatbot: it is an enterprise operating system whose moat is provable governance. Here is exactly what we do — and what we do not (yet) claim to do.

The differentiator

Verifiable work, not promises

Every agent action produces a chained SHA-256 cryptographic certificate (plan → execution → result → evaluation → signature). The chain is tamper-proof: altering one certificate breaks the signature of the following ones. Anyone — auditor, buyer, regulator — can verify it publicly, with no internal access.

Try public verification

Data Vault — 7 layers

Defense in depth. Every status is stated honestly.

1

Encryption

In production

AES-256 at rest, TLS 1.3 in transit (Supabase Vault).

2

Data minimization

In production

The LLM receives data sanitized by level (PII masked / metadata / air-gap) via data-minimizer.

3

RLS isolation

In production

Row-Level Security on every table, keyed on org_id. Strict multi-tenant isolation.

4

Audit trail

In production

Append-only logs + tamper-proof certificate chain (chained SHA-256).

5

Key rotation

In production

JWT rotation (1h) + API keys (90d).

6

Emergency stop button

In production

Freeze all agents in under 5s (Owner) — /api/emergency/shutdown.

7

Air Gap

Planned

Docker/K8s deployment on the client's infrastructure, zero outbound data.

Governance

Verifiable work

Every action produces a chained SHA-256 certificate, publicly verifiable on /verify — the antithesis of agent-washing.

Company Constitution

Versioned governance rules, applied at every step of the agent execution cycle.

Policy Engine

Every tool call is checked against company policies BEFORE execution; otherwise it escalates.

Explainable Trust Score

A 0–100 autonomy score, decomposed and auditable, anchored in the certificate chain — never a black box.

Runtime guardrails

Prompt-injection / jailbreak detection on all untrusted input (visitors, RAG, SDK).

Compliance roadmap

Full transparency: we never claim a certification we have not obtained. "Aligned" means our architecture is mapped to the framework, without an independent audit.

FrameworkStatusWhere we stand
SOC 2 Type IIIn progressTechnical controls in place (encryption, RLS, audit, rotation). Independent audit to be scheduled.
ISO/IEC 27001PlannedISMS to be formalized; the underlying technical controls are already deployed.
ISO/IEC 42001 (AI)PlannedAI management system — governance (Constitution, Trust Score, Verifiable Work) lays the foundations.
EU AI ActAligned (not audited)Traceability, transparency and tamper-proof logs mapped to the requirements; risk classification by use case.
NIST AI RMFAligned (not audited)Govern/Map/Measure/Manage functions covered by the Constitution, Policy Engine and Trust Score.
Law 25 (Quebec) / PIPEDAAligned (not audited)Data minimization, Canadian residency targeted, right to erasure via RLS + purge.
Data protection (Africa)Aligned (not audited)NDPA (Nigeria), DPA (Kenya), APDP (Benin), POPIA, etc.: per-tenant residency (af-south-1 / OVH Casablanca), African PII minimization, consent — Sovereignty Pact A1.

A security question or a vendor questionnaire?

Our governance architecture is built to pass enterprise procurement reviews. Let’s talk.

Get started