Security & Compliance

Claims an auditor can check.

Built for organisations that must answer for their data. Everything on this page describes shipped mechanisms, and the trust library puts them in writing, readable right here. Nothing is claimed before it is held; each certification page shows where its track stands.

One client. One deployment. One boundary.

There is no shared platform. Each client runs their own instance with their own database; documents, conversations, permissions and audit records never share storage with anyone else's. One database also means one backup scope, one encryption scope and one data map.

Isolation is the deployment model, not a configuration option, there is no multi-tenant mode to misconfigure.

Tenancy

Single-tenant per client, by decision, not a configuration option

State

One PostgreSQL: index, conversations, audit log, job queue

Credentials

Connector and channel secrets are write-only, accepted, used, never displayed again

Webhooks

Every platform's signature scheme verified; unverified calls are rejected

Hosting

EU data centre under our management, or your own Linux server, same product

What leaves, and what never does.

Indexing (reading and embedding your documents) runs entirely inside your deployment, in every configuration. The corpus never leaves it to be indexed.

The fullest posture keeps generation home too: a self-hosted deployment answering on a self-hosted, open-weight AI model, on your own hardware. Documents, index, questions and answers live and die inside your boundary; there is nothing to send and nobody to send it to.

Deployments that prefer it, managed ones typically, use the Naxis AI service instead, and the safety record is written down: it receives only the question and the permission-filtered excerpts retrieval selected, never the corpus, never other people's documents; nothing is retained after the answer returns and nothing is used for training, under a data-processing agreement with zero-retention terms. Deployments hold no AI-service credentials at all: generation rides a metered relay we operate, so a compromised server cannot leak a key that was never on it.

Index

Computed and stored inside the deployment, always

Self-hosted AI

Open-weight model on your own hardware; nothing leaves the boundary

Naxis AI service

The managed option: question + permitted excerpts only, zero retention, no training, under DPA

Keys

No AI-service credentials on any instance; the relay meters and can revoke centrally

Traceability

Every answer is stamped internally with the engine version that produced it

Permissions inside every query.
A record that proves itself.

Document access is group-based, and the filter lives inside every database query the assistant makes, retrieval, reading, browsing, on every channel and API. No surface can widen access, because no surface runs above the filter.

Enforcement

Group ACL in the WHERE clause of every retrieval and read

Passwords

PBKDF2-SHA256 at 600,000 iterations; timing-equalised checks; lockout on failures

Sessions

Opaque tokens, hash-stored, HttpOnly cookies; revoked on deactivation or password change

Accounts

Invitation-based activation; one-time links; administrators never see a password

Every consequential event, every question and what it cited, every sync, permission change, erasure, export, sign-in, lands in an append-only audit log where each entry carries the hash of the one before. Rows cannot be edited or deleted; verification recomputes the whole chain on one click.

Integrity

SHA-256 hash chain; database trigger blocks edits and deletes

Verification

One click in the console, or the operator command line

Coverage

Queries with cited passages, syncs, ACL changes, erasures, exports, sign-ins

Modes

Full, or metadata-only (no message content stored at all)

Security as a pipeline, not a promise.

Two standing pipelines carry the product: one gates every release before any client sees it, one runs against the fleet continuously. Both are the same for every deployment, managed and self-hosted install the identical, verified artifact.

Rights with a mechanism behind them.

Every deployment generates its own GDPR Article 30 manifest from live configuration, and erasure is deletion, not flagging, a title or file path can identify a person, so no tombstone may remain. The full mapping, article by article, is on the GDPR page.

Art. 15 / 20

Self-service "Export my data" JSON; admin subject-access export

Art. 17

Hard deletion per person or per document, no residue, index included

Art. 28 / 30

DPA per deployment; the manifest generated from what actually runs

Breach

Tamper-evident log + per-subject export scope; 72-hour support commitment

Under the EU AI Act the assistant is transparent by construction: it tells people AI is answering, shows where every answer came from, and is contractually kept away from Annex III high-risk uses. The position, article by article, is on the EU AI Act page.

Art. 50

AI-interaction disclosure on chat, sign-in, invitations and the CLI

Art. 4

The in-product help centre as the deployer's AI-literacy resource

Annex III

High-risk uses contractually excluded

Cookies

Product: one strictly-necessary session cookie. This site: none signed-out

In writing, on request.

Overview Sent on request
Security & architecture overview

How a deployment is built: the single-tenant boundary, the permission model, the audit chain and the AI data flow: the document a security review starts with.

Request to see

An account action, the request files under your Naxis account, and the answer arrives on its thread.

Template Sent on request
Data Processing Agreement (Art. 28)

The DPA template every deployment is contracted under: subject matter, sub-processor notice procedure, audit rights, deletion on termination. Signed per client; shared under NDA where appropriate.

Request to see

An account action, the request files under your Naxis account, and the answer arrives on its thread.

Service Sent on request
Your security questionnaire, answered

Send your own questionnaire: CAIQ, SIG, or your in-house sheet, in the request note. Answers come from the architecture, not a boilerplate script.

Request to see

An account action, the request files under your Naxis account, and the answer arrives on its thread.

The full desk, every requestable document, with the status of your own requests, lives in your account.

Read it here.

The documents reviewers ask for, frameworks, legal structure, technical record, readable on this page, no request forms in the way. Signed copies are an account request away.

Certifications & frameworks

GDPR: how a deployment complies Read it here

The rights articles as product mechanisms: export, erasure, records of processing, each one built in, none of it paperwork after the fact.

Every Naxis deployment is a single-tenant system processing only the client's own documents, on infrastructure the client chooses. GDPR compliance is implemented as product mechanisms, not policies:

Art. 15 · access
Self-service "Export my data" for every signed-in person (JSON, complete), plus an administrator subject-access export for any subject the deployment knows.
Art. 17 · erasure
Hard delete, everywhere: a person's conversations, or a single document, are removed from the store and the search index in one action. Erasure is itself recorded in the audit log; no tombstone data remains.
Art. 28 · processing
Each deployment is contracted under a Data Processing Agreement including the sub-processor notice procedure (see Legal documents below).
Art. 30 · records
The deployment generates its own record-of-processing manifest from the configuration that actually runs (retention values, sub-processors, technical measures), so the paperwork cannot drift from reality.
Retention
Conversation and audit retention are explicit, configurable values enforced by a nightly job; the live values are shown read-only in the admin console.

The generated manifest for a specific deployment is available to its administrator at any time; a sample is in Technical documentation below.

Need it as a signed document? Request a copy from your account, the answer arrives on your own thread.

EU AI Act: position & measures Read it here

Transparency by construction: AI-interaction disclosure on every surface, an AI-literacy resource in the product, high-risk uses contractually excluded.

Article 50
Every conversational surface (web chat, sign-in, invitations, messaging channels) discloses that answers are AI-generated and cited.
Article 4
The in-product help centre serves as the deployer's AI-literacy resource: how answers are produced, what citations mean, what the assistant refuses and why.
Annex III
Deployments are contractually excluded from high-risk uses; the product is a knowledge engine over business documents, and the terms keep it that.
Human oversight
Answers cite their sources or decline. Nothing executes actions; a human reads, verifies against the cited passage, and decides.
ISO/IEC 27001 Not yet held

The control themes the standard expects, access control, cryptography, operations security, supplier relationships, are shipped mechanisms described in Technical documentation.

This artifact is not claimed until it exists. Its own page shows exactly where the track stands. File a standing request from your account, it is fulfilled the day the artifact lands, and we answer security questionnaires directly in the meantime.

SOC 2 Type II Not yet held

Until a report exists nothing is claimed here; reviewers can assess the same controls directly from the architecture overview below.

This artifact is not claimed until it exists. Its own page shows exactly where the track stands. File a standing request from your account, it is fulfilled the day the artifact lands, and we answer security questionnaires directly in the meantime.

Legal documents

Data Processing Agreement (Art. 28) Read it here

The DPA every deployment is contracted under, subject matter, duration, sub-processor notice procedure, audit rights, deletion on termination.

The signed DPA is executed per client. Its structure, so your legal team knows what to expect:

  • Subject matter & duration, processing of the client's business documents for the sole purpose of answering the client's own users; runs with the service agreement.
  • Nature & purpose, indexing, retrieval and answer generation with citations; no secondary use, no training on client data.
  • Sub-processors, listed by category with a written notice procedure before any change (see the sub-processor notice below).
  • Security measures, the technical and organisational measures, referencing the deployment's own generated manifest so the annex matches the running configuration.
  • Deletion, on termination, the deployment and its data are destroyed or handed over; self-hosted clients hold the data throughout.
  • Audit, information and audit rights, with the audit log and manifest as first-class evidence.

Request the full template, or a signed copy for review under NDA, through the contact page; it is provided as a matter of course.

Need it as a signed document? Request a copy from your account, the answer arrives on your own thread.

Sub-processor notice Read it here

At most two categories exist, and the fullest configuration, self-hosted with self-hosted AI, has none.

AI generation
The primary configuration keeps generation in-house: a self-hosted deployment answering on a self-hosted, open-weight AI model has no AI sub-processor at all. Deployments using the Naxis AI service instead send the question and the permission-filtered excerpts under a data-processing agreement with zero-retention terms: nothing is stored after the answer returns, nothing trains any model, and no client identity accompanies the request.
Hosting
Managed deployments run on an EU data-centre provider under their DPA; the instance, its database and its documents live on a server dedicated to that client. Self-hosted deployments have no hosting sub-processor at all, the client's own infrastructure carries everything.

Changes to either category follow the DPA's written notice procedure. There are no analytics, advertising or telemetry processors, the product ships none.

Need it as a signed document? Request a copy from your account, the answer arrives on your own thread.

Technical documentation

Security & architecture overview Read it here

One client, one deployment, one boundary, what that means concretely: containers, database, credentials, the AI boundary and the audit chain.

Tenancy

Each client runs their own complete instance: application, worker, database and document store in isolated containers on a machine that serves no other client. There is no shared platform, no pooled database, no cross-tenant anything, isolation is the deployment model, not a configuration option.

Data at rest

Store
One PostgreSQL database per deployment: documents, search index, conversations, audit log, job queue.
Credentials
Connector and channel secrets are write-only after entry: accepted, used for syncing, never displayed again, and redacted from every API response.
Webhooks
Every messaging platform's signature scheme is verified; unsigned or mis-signed calls are rejected before any processing.

The AI boundary

Indexing (reading and embedding documents) runs entirely inside the deployment. Generation follows the deployment's configuration: the fullest posture is a self-hosted deployment answering on a self-hosted, open-weight AI model, where nothing leaves the boundary at all. Deployments using the Naxis AI service send the question and the permission-filtered excerpts (zero-retention terms, see sub-processors); the model never sees documents the asking person cannot see, because permission filtering happens before the request leaves.

In every configuration: your data is not used to train models, and nothing is retained after the answer returns.

Permissions

Access is group-based and enforced inside every query the assistant makes, the filter lives in the retrieval itself, not in any surface. Accounts activate by invitation link; administrators never see or set a password. Channel guests receive nothing until groups are explicitly opened to them.

The audit chain

Every consequential event, questions, answers with their citations, administrative actions, syncs, erasures, lands on an append-only, hash-chained log. Verification recomputes the whole chain on demand from the console; a broken link is impossible to hide. Rows cannot be edited or deleted; retention prunes whole aged spans and records that it did.

Updates

Releases are versioned images; deployments install them in a quiet window after a safety backup and roll back on their own if the health check fails. What changed in each release is shown in the console in plain language.

Need it as a signed document? Request a copy from your account, the answer arrives on your own thread.

Data flow & residency Read it here

What leaves the deployment, what never does, and where things physically live.

Never leaves
Documents at rest, the search index, conversation history, the audit log, user accounts and permissions.
Leaves per answer
With self-hosted AI: nothing. With the Naxis AI service: the question plus the permission-filtered excerpts needed to answer it, under zero-retention terms. Nothing else, no identifiers.
Residency
Managed hosting runs in EU data centres. Self-hosted deployments run wherever the client puts them, the product has no home-calling dependencies for its core function.
This website
Runs no analytics or third-party scripts; the only cookie is the strictly-necessary account session. The product itself sets exactly one strictly-necessary session cookie. The interactive demo records usage under an explicit opt-in (see the privacy notice).

Need it as a signed document? Request a copy from your account, the answer arrives on your own thread.

Compliance manifest (sample) Read it here

Every deployment renders one of these from its own live configuration, this is the shape of it.

Generated, not written: the values below come from a deployment's actual configuration at generation time.

Deployment
client-name · single-tenant · region as contracted
Data categories
Business documents from connected sources; user accounts (name, email); conversation history; audit events
Retention
Conversations: 90 days (configurable) · audit log: 730 days (configurable) · both pruned nightly, prune runs logged
Sub-processors
None (self-hosted AI), or the Naxis AI service (zero-retention DPA) · hosting provider, or none when self-hosted
Rights handling
Art. 15 export: self-service + admin · Art. 17 erasure: hard delete incl. index · Art. 30: this manifest
Technical measures
Isolated containers · TLS in transit · hash-chained audit log · write-only credentials · signature-verified webhooks

Administrators export the real manifest for their deployment from the console at any time.

Need it as a signed document? Request a copy from your account, the answer arrives on your own thread.

Need something that isn't here yet? Name it from your account or ask directly, security questionnaires are answered from the architecture, not a script.

What reviewers ask first

Is Naxis Assistant GDPR-compliant?

Compliance is implemented as product mechanisms, not policies: self-service data export (Art. 15/20), hard-delete erasure that removes records from store and index alike (Art. 17), a DPA with a sub-processor notice procedure (Art. 28), and a record-of-processing manifest each deployment generates from its own live configuration (Art. 30). The details are readable in the trust library on this page.

Where is our data stored, and who can see it?

Each client runs a single-tenant deployment, own instance, own database, in an EU data centre under our management, or on your own servers. Documents at rest, the index, conversations and the audit log never leave the deployment. Nobody at Naxis reads inside your instance without a consent you grant per support ticket.

Does our data train AI models?

No, in any configuration. The fullest posture keeps everything home: a self-hosted deployment generating answers on a self-hosted, open-weight AI model, where nothing leaves your boundary at all. Deployments that use the Naxis AI service instead send only the question and the permission-filtered excerpts, nothing is retained after the answer returns and nothing trains any model, in writing, under zero-retention terms.

Are you ISO 27001 certified or SOC 2 audited?

Neither is claimed anywhere on this site, and we say so plainly. What exists today is the control work itself, shipped and reviewable on this page, and a status page for each track that shows exactly where it stands, station by station. A standing request from your account gets you each artifact the day it exists.

Will you answer our security questionnaire?

Yes, from the architecture, not a script. File it as a document request from your account (or send it through the contact page) and the answers come back on your own thread.

Put your DPO in the room.

Bring the questionnaire, the counsel and the IT lead, reviews are answered from the architecture, on your own thread.