Claims an auditor can check.
Built for organisations that must answer for their data. Everything on this page describes shipped mechanisms, and the trust library puts them in writing, readable right here. Nothing is claimed before it is held; each certification page shows where its track stands.
"Where do we stand with Alfamart?", answered, 2 passages cited
Drive swept: 3 files re-indexed, 1 removal pruned
Subject #182 hard-deleted: store and index, no residue
Every link recomputed, first entry to last.
One client. One deployment. One boundary.
There is no shared platform. Each client runs their own instance with their own database; documents, conversations, permissions and audit records never share storage with anyone else's. One database also means one backup scope, one encryption scope and one data map.
Isolation is the deployment model, not a configuration option, there is no multi-tenant mode to misconfigure.
Single-tenant per client, by decision, not a configuration option
One PostgreSQL: index, conversations, audit log, job queue
Connector and channel secrets are write-only, accepted, used, never displayed again
Every platform's signature scheme verified; unverified calls are rejected
EU data centre under our management, or your own Linux server, same product
What leaves, and what never does.
Indexing (reading and embedding your documents) runs entirely inside your deployment, in every configuration. The corpus never leaves it to be indexed.
The fullest posture keeps generation home too: a self-hosted deployment answering on a self-hosted, open-weight AI model, on your own hardware. Documents, index, questions and answers live and die inside your boundary; there is nothing to send and nobody to send it to.
Deployments that prefer it, managed ones typically, use the Naxis AI service instead, and the safety record is written down: it receives only the question and the permission-filtered excerpts retrieval selected, never the corpus, never other people's documents; nothing is retained after the answer returns and nothing is used for training, under a data-processing agreement with zero-retention terms. Deployments hold no AI-service credentials at all: generation rides a metered relay we operate, so a compromised server cannot leak a key that was never on it.
Computed and stored inside the deployment, always
Open-weight model on your own hardware; nothing leaves the boundary
The managed option: question + permitted excerpts only, zero retention, no training, under DPA
No AI-service credentials on any instance; the relay meters and can revoke centrally
Every answer is stamped internally with the engine version that produced it
Permissions inside every query.
A record that proves itself.
Document access is group-based, and the filter lives inside every database query the assistant makes, retrieval, reading, browsing, on every channel and API. No surface can widen access, because no surface runs above the filter.
Group ACL in the WHERE clause of every retrieval and read
PBKDF2-SHA256 at 600,000 iterations; timing-equalised checks; lockout on failures
Opaque tokens, hash-stored, HttpOnly cookies; revoked on deactivation or password change
Invitation-based activation; one-time links; administrators never see a password
Every consequential event, every question and what it cited, every sync, permission change, erasure, export, sign-in, lands in an append-only audit log where each entry carries the hash of the one before. Rows cannot be edited or deleted; verification recomputes the whole chain on one click.
SHA-256 hash chain; database trigger blocks edits and deletes
One click in the console, or the operator command line
Queries with cited passages, syncs, ACL changes, erasures, exports, sign-ins
Full, or metadata-only (no message content stored at all)
Security as a pipeline, not a promise.
Two standing pipelines carry the product: one gates every release before any client sees it, one runs against the fleet continuously. Both are the same for every deployment, managed and self-hosted install the identical, verified artifact.
Rights with a mechanism behind them.
Every deployment generates its own GDPR Article 30 manifest from live configuration, and erasure is deletion, not flagging, a title or file path can identify a person, so no tombstone may remain. The full mapping, article by article, is on the GDPR page.
Self-service "Export my data" JSON; admin subject-access export
Hard deletion per person or per document, no residue, index included
DPA per deployment; the manifest generated from what actually runs
Tamper-evident log + per-subject export scope; 72-hour support commitment
Under the EU AI Act the assistant is transparent by construction: it tells people AI is answering, shows where every answer came from, and is contractually kept away from Annex III high-risk uses. The position, article by article, is on the EU AI Act page.
AI-interaction disclosure on chat, sign-in, invitations and the CLI
The in-product help centre as the deployer's AI-literacy resource
High-risk uses contractually excluded
Product: one strictly-necessary session cookie. This site: none signed-out
Frameworks, with their status on the plate.
ACT BUILT-IN The assistant declares itself on every surface; answers stay grounded in your record. The position ISO
27001 TRACK UNDERWAY The control themes are shipped mechanisms today; the track page shows where certification stands. See where it stands SOC 2 TRACK UNDERWAY A Type II is evidence over a live audit window; the track page shows where the engagement stands. See where it stands
Nothing here is claimed before it is held. The ISO 27001 and SOC 2 pages show exactly where each track stands, and a standing request from your account brings you each artifact the day it exists.
In writing, on request.
How a deployment is built: the single-tenant boundary, the permission model, the audit chain and the AI data flow: the document a security review starts with.
An account action, the request files under your Naxis account, and the answer arrives on its thread.
The DPA template every deployment is contracted under: subject matter, sub-processor notice procedure, audit rights, deletion on termination. Signed per client; shared under NDA where appropriate.
An account action, the request files under your Naxis account, and the answer arrives on its thread.
Send your own questionnaire: CAIQ, SIG, or your in-house sheet, in the request note. Answers come from the architecture, not a boilerplate script.
An account action, the request files under your Naxis account, and the answer arrives on its thread.
The full desk, every requestable document, with the status of your own requests, lives in your account.
Read it here.
The documents reviewers ask for, frameworks, legal structure, technical record, readable on this page, no request forms in the way. Signed copies are an account request away.
Certifications & frameworks
GDPR: how a deployment complies Read it here
The rights articles as product mechanisms: export, erasure, records of processing, each one built in, none of it paperwork after the fact.
Every Naxis deployment is a single-tenant system processing only the client's own documents, on infrastructure the client chooses. GDPR compliance is implemented as product mechanisms, not policies:
- Art. 15 · access
- Self-service "Export my data" for every signed-in person (JSON, complete), plus an administrator subject-access export for any subject the deployment knows.
- Art. 17 · erasure
- Hard delete, everywhere: a person's conversations, or a single document, are removed from the store and the search index in one action. Erasure is itself recorded in the audit log; no tombstone data remains.
- Art. 28 · processing
- Each deployment is contracted under a Data Processing Agreement including the sub-processor notice procedure (see Legal documents below).
- Art. 30 · records
- The deployment generates its own record-of-processing manifest from the configuration that actually runs (retention values, sub-processors, technical measures), so the paperwork cannot drift from reality.
- Retention
- Conversation and audit retention are explicit, configurable values enforced by a nightly job; the live values are shown read-only in the admin console.
The generated manifest for a specific deployment is available to its administrator at any time; a sample is in Technical documentation below.
Need it as a signed document? Request a copy from your account, the answer arrives on your own thread.
EU AI Act: position & measures Read it here
Transparency by construction: AI-interaction disclosure on every surface, an AI-literacy resource in the product, high-risk uses contractually excluded.
- Article 50
- Every conversational surface (web chat, sign-in, invitations, messaging channels) discloses that answers are AI-generated and cited.
- Article 4
- The in-product help centre serves as the deployer's AI-literacy resource: how answers are produced, what citations mean, what the assistant refuses and why.
- Annex III
- Deployments are contractually excluded from high-risk uses; the product is a knowledge engine over business documents, and the terms keep it that.
- Human oversight
- Answers cite their sources or decline. Nothing executes actions; a human reads, verifies against the cited passage, and decides.
ISO/IEC 27001 Not yet held
The control themes the standard expects, access control, cryptography, operations security, supplier relationships, are shipped mechanisms described in Technical documentation.
This artifact is not claimed until it exists. Its own page shows exactly where the track stands. File a standing request from your account, it is fulfilled the day the artifact lands, and we answer security questionnaires directly in the meantime.
SOC 2 Type II Not yet held
Until a report exists nothing is claimed here; reviewers can assess the same controls directly from the architecture overview below.
This artifact is not claimed until it exists. Its own page shows exactly where the track stands. File a standing request from your account, it is fulfilled the day the artifact lands, and we answer security questionnaires directly in the meantime.
Legal documents
Data Processing Agreement (Art. 28) Read it here
The DPA every deployment is contracted under, subject matter, duration, sub-processor notice procedure, audit rights, deletion on termination.
The signed DPA is executed per client. Its structure, so your legal team knows what to expect:
- Subject matter & duration, processing of the client's business documents for the sole purpose of answering the client's own users; runs with the service agreement.
- Nature & purpose, indexing, retrieval and answer generation with citations; no secondary use, no training on client data.
- Sub-processors, listed by category with a written notice procedure before any change (see the sub-processor notice below).
- Security measures, the technical and organisational measures, referencing the deployment's own generated manifest so the annex matches the running configuration.
- Deletion, on termination, the deployment and its data are destroyed or handed over; self-hosted clients hold the data throughout.
- Audit, information and audit rights, with the audit log and manifest as first-class evidence.
Request the full template, or a signed copy for review under NDA, through the contact page; it is provided as a matter of course.
Need it as a signed document? Request a copy from your account, the answer arrives on your own thread.
Sub-processor notice Read it here
At most two categories exist, and the fullest configuration, self-hosted with self-hosted AI, has none.
- AI generation
- The primary configuration keeps generation in-house: a self-hosted deployment answering on a self-hosted, open-weight AI model has no AI sub-processor at all. Deployments using the Naxis AI service instead send the question and the permission-filtered excerpts under a data-processing agreement with zero-retention terms: nothing is stored after the answer returns, nothing trains any model, and no client identity accompanies the request.
- Hosting
- Managed deployments run on an EU data-centre provider under their DPA; the instance, its database and its documents live on a server dedicated to that client. Self-hosted deployments have no hosting sub-processor at all, the client's own infrastructure carries everything.
Changes to either category follow the DPA's written notice procedure. There are no analytics, advertising or telemetry processors, the product ships none.
Need it as a signed document? Request a copy from your account, the answer arrives on your own thread.
Technical documentation
Security & architecture overview Read it here
One client, one deployment, one boundary, what that means concretely: containers, database, credentials, the AI boundary and the audit chain.
Tenancy
Each client runs their own complete instance: application, worker, database and document store in isolated containers on a machine that serves no other client. There is no shared platform, no pooled database, no cross-tenant anything, isolation is the deployment model, not a configuration option.
Data at rest
- Store
- One PostgreSQL database per deployment: documents, search index, conversations, audit log, job queue.
- Credentials
- Connector and channel secrets are write-only after entry: accepted, used for syncing, never displayed again, and redacted from every API response.
- Webhooks
- Every messaging platform's signature scheme is verified; unsigned or mis-signed calls are rejected before any processing.
The AI boundary
Indexing (reading and embedding documents) runs entirely inside the deployment. Generation follows the deployment's configuration: the fullest posture is a self-hosted deployment answering on a self-hosted, open-weight AI model, where nothing leaves the boundary at all. Deployments using the Naxis AI service send the question and the permission-filtered excerpts (zero-retention terms, see sub-processors); the model never sees documents the asking person cannot see, because permission filtering happens before the request leaves.
In every configuration: your data is not used to train models, and nothing is retained after the answer returns.
Permissions
Access is group-based and enforced inside every query the assistant makes, the filter lives in the retrieval itself, not in any surface. Accounts activate by invitation link; administrators never see or set a password. Channel guests receive nothing until groups are explicitly opened to them.
The audit chain
Every consequential event, questions, answers with their citations, administrative actions, syncs, erasures, lands on an append-only, hash-chained log. Verification recomputes the whole chain on demand from the console; a broken link is impossible to hide. Rows cannot be edited or deleted; retention prunes whole aged spans and records that it did.
Updates
Releases are versioned images; deployments install them in a quiet window after a safety backup and roll back on their own if the health check fails. What changed in each release is shown in the console in plain language.
Need it as a signed document? Request a copy from your account, the answer arrives on your own thread.
Data flow & residency Read it here
What leaves the deployment, what never does, and where things physically live.
- Never leaves
- Documents at rest, the search index, conversation history, the audit log, user accounts and permissions.
- Leaves per answer
- With self-hosted AI: nothing. With the Naxis AI service: the question plus the permission-filtered excerpts needed to answer it, under zero-retention terms. Nothing else, no identifiers.
- Residency
- Managed hosting runs in EU data centres. Self-hosted deployments run wherever the client puts them, the product has no home-calling dependencies for its core function.
- This website
- Runs no analytics or third-party scripts; the only cookie is the strictly-necessary account session. The product itself sets exactly one strictly-necessary session cookie. The interactive demo records usage under an explicit opt-in (see the privacy notice).
Need it as a signed document? Request a copy from your account, the answer arrives on your own thread.
Compliance manifest (sample) Read it here
Every deployment renders one of these from its own live configuration, this is the shape of it.
Generated, not written: the values below come from a deployment's actual configuration at generation time.
- Deployment
- client-name · single-tenant · region as contracted
- Data categories
- Business documents from connected sources; user accounts (name, email); conversation history; audit events
- Retention
- Conversations: 90 days (configurable) · audit log: 730 days (configurable) · both pruned nightly, prune runs logged
- Sub-processors
- None (self-hosted AI), or the Naxis AI service (zero-retention DPA) · hosting provider, or none when self-hosted
- Rights handling
- Art. 15 export: self-service + admin · Art. 17 erasure: hard delete incl. index · Art. 30: this manifest
- Technical measures
- Isolated containers · TLS in transit · hash-chained audit log · write-only credentials · signature-verified webhooks
Administrators export the real manifest for their deployment from the console at any time.
Need it as a signed document? Request a copy from your account, the answer arrives on your own thread.
Need something that isn't here yet? Name it from your account or ask directly, security questionnaires are answered from the architecture, not a script.
What reviewers ask first
Is Naxis Assistant GDPR-compliant?
Compliance is implemented as product mechanisms, not policies: self-service data export (Art. 15/20), hard-delete erasure that removes records from store and index alike (Art. 17), a DPA with a sub-processor notice procedure (Art. 28), and a record-of-processing manifest each deployment generates from its own live configuration (Art. 30). The details are readable in the trust library on this page.
Where is our data stored, and who can see it?
Each client runs a single-tenant deployment, own instance, own database, in an EU data centre under our management, or on your own servers. Documents at rest, the index, conversations and the audit log never leave the deployment. Nobody at Naxis reads inside your instance without a consent you grant per support ticket.
Self-hosted install, what it needs Request the architecture record
Does our data train AI models?
No, in any configuration. The fullest posture keeps everything home: a self-hosted deployment generating answers on a self-hosted, open-weight AI model, where nothing leaves your boundary at all. Deployments that use the Naxis AI service instead send only the question and the permission-filtered excerpts, nothing is retained after the answer returns and nothing trains any model, in writing, under zero-retention terms.
Are you ISO 27001 certified or SOC 2 audited?
Neither is claimed anywhere on this site, and we say so plainly. What exists today is the control work itself, shipped and reviewable on this page, and a status page for each track that shows exactly where it stands, station by station. A standing request from your account gets you each artifact the day it exists.
Will you answer our security questionnaire?
Yes, from the architecture, not a script. File it as a document request from your account (or send it through the contact page) and the answers come back on your own thread.
Put your DPO in the room.
Bring the questionnaire, the counsel and the IT lead, reviews are answered from the architecture, on your own thread.