Security

Your data stays yours. End to end.

Nexadata pairs AI-assisted reasoning with deterministic execution, so raw customer data never reaches a language model and never leaves the platform boundary. Zero data retention, SOC 2 Type II, and enterprise access controls come standard.

SOC 2 Type II Zero Data Retention SSO / SAML / RBAC

How your data is handled

The model reasons about intent. It never touches your data.

You describe what you want in plain language. Only abstracted, structured context ever reaches the language model, and it can be anonymized. Every byte of raw data is ingested, transformed, and executed inside the Nexadata platform, deterministically, within your boundary.

Inside the Nexadata platform
Raw records
Transformations
Mappings

Ingestion, transformation, and execution all happen here, with native deterministic primitives. Raw customer data never leaves this boundary.

Abstracted context only

Reasoning model

Anthropic Claude

Reasons about intent and proposes a plan. It never processes raw data and execution never requires token usage.

Zero data retention

Three independent layers of retention control

Choose the control that fits your policy, or combine them. Each layer stands on its own, so nothing about your prompts or context has to persist anywhere you do not want it to.

01 At the platform

ZDR mode

A configurable setting that keeps AI prompts and metadata out of persistent storage. Context is used in flight, then discarded.

02 At the infrastructure

ZDR via Amazon Bedrock

Claude inference routes through Amazon Bedrock, which does not store prompts or completions. Per request, with no separate enterprise contract to negotiate.

03 Your key, your terms

Bring your own key

Use your own Anthropic Claude API key, applied across your tenant. Usage is governed by your direct relationship with Anthropic.

Compliance and governance

Enterprise controls, built in

The certifications, access controls, and audit trails your security team expects, with a human approving every change before it touches your data.

SOC 2 Type II

Independently audited controls for security, availability, and confidentiality. The full report lives in our Trust Center.

SSO and SAML

Single sign-on with SAML and OAuth2, so access follows the identity provider and policies you already run.

Role-based access control

RBAC scopes what each user can see and do, down to the workspace and the workflow.

Human in the loop

Every transformation and mapping is proposed for review. Nothing runs against your data until a person approves it.

Full lineage and audit

Complete observability, data lineage, and audit history for every run, so you can trace exactly what happened and when.

Deterministic execution

All processing uses native, repeatable platform primitives. The same inputs always produce the same trusted output.

Technical foundation

A platform engineered to keep data under your control

Cloud-agnostic

Deployable on AWS, Azure, or GCP. Currently hosted on AWS.

Monolithic and containerized

A single, tightly integrated containerized service, not a sprawl of loosely coupled parts.

Multi-tenant SaaS

A modern multi-tenant platform with isolation and access controls built in.

Public and private REST APIs

Documented REST APIs for extensibility and integration into your own stack.

See the controls for yourself

Our Trust Center has the live status of every control, certification, and policy. Have a specific requirement? Talk to our security team.