Security & Compliance · SOC 2 Type II

Audit planned. Claims withheld.

We are working toward a SOC 2 Type II report. Until an auditor issues one, this page claims nothing, it shows where the engagement stands and which controls you can already assess. A standing request brings you the report the day it exists.

The road to a Type II, honestly drawn.

  1. 01 · Done Controls designed & shipped

    The mechanisms the criteria expect (isolation, filtered retrieval, the audit chain, the release gate) are in the product, not on a slide.

  2. 02 · In progress Readiness & evidence

    Evidence collection wired into the pipelines that already run: signed releases, heartbeats, audit exports, access records.

  3. 03 · Next Observation window

    The months a Type II is made of: the auditor watches controls operate, not a snapshot of them.

  4. 04 · Then Report issued

    The report lands with everyone whose request is standing, under NDA, as SOC 2 reports are.

No promised dates. The current engagement state is shareable at any time from your account.

The trust criteria, mapped to what runs.

Security

Single-tenant isolation; permission filters inside every query; signed webhooks; per-IP backoff and challenges on sign-in; network-level intrusion ban lists at the managed edge

Availability

Signed heartbeats every 15 minutes with disturbance events; self-healing background jobs; safety backup before each update and automatic rollback on failed health checks

Confidentiality

Write-only secrets; self-hosted AI keeps generation in-house, and the Naxis AI service runs zero-retention; no shared storage between clients; no AI-service keys on instances

Processing integrity

Cite-or-abstain answers; deterministic date handling; a hash-chained audit log with one-click verification of the whole chain

Every row is expanded in the trust library and the architecture overview, reviewable before any auditor confirms it.

What to request, today and the day it lands.

Report Not yet held
SOC 2 Type II report

No report exists yet and nothing is claimed until it does; the SOC 2 page shows exactly where the engagement stands. A standing request is fulfilled when the report is issued; the control record is reviewable today.

Request it when ready

An account action, the request files under your Naxis account, and the answer arrives on its thread.

Overview Sent on request
Security & architecture overview

How a deployment is built: the single-tenant boundary, the permission model, the audit chain and the AI data flow: the document a security review starts with.

Request to see

An account action, the request files under your Naxis account, and the answer arrives on its thread.

Service Sent on request
Your security questionnaire, answered

Send your own questionnaire: CAIQ, SIG, or your in-house sheet, in the request note. Answers come from the architecture, not a boilerplate script.

Request to see

An account action, the request files under your Naxis account, and the answer arrives on its thread.

SOC 2 status, answered

Do you have a SOC 2 report?

Not yet, and we say so plainly: the SOC 2 Type II engagement is in preparation and no report is claimed until one is issued. A standing request from your account means the report reaches you the day it exists.

Why does a Type II report take so long?

Because that is what makes it worth reading. A Type I describes controls at a point in time; a Type II has an auditor examine evidence across a live observation window of months. The window cannot be compressed, evidence has to accrue.

What can our security team review before the report exists?

The same controls the audit will examine: the security & architecture overview, the trust library, the hash-chained audit log design, the release gate, and your own questionnaire answered from the architecture. All requestable from your account today.

Which Trust Services Criteria will be in scope?

Security as the required baseline, with Availability, Confidentiality and Processing integrity mapped below, the final scope is stated with the engagement, and this page will say exactly what the report covers, no more.

Can we buy before the report exists?

Yes, organisations that must answer for their data do it by assessing the mechanisms directly and contracting the DPA. The report, when issued, confirms what you already reviewed; a standing request keeps you first in line.

Assess the controls yourself.

The report, when it comes, will confirm what you can already review, not reveal it.