Third Party Index

Snapshot 21149

Document
Subprocessor list
URL
https://nextfluent.com/trust#subprocessors
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
browser
Size
170919 bytes
SHA-256 (raw)
5803a5bb84ac1f099908129dee52f528c448b8dfff01a8f935d18599f3b54a68
SHA-256 (normalized text)
c25d34808c3dfa030d3ff4dca51db9a33b19131540746a7af74b26bea7b6cacf

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Skip to main content
v6 · 2026 · Edition 01
§00 / 06·Trust Center
Defensible by design.
Security posture, data handling, certifications, and live status — all in one place. NextFluent is the OS for defensible decisions; this page is how we earn that name.
Live system statusDownload DPA
[email protected] · Responsible disclosure /security/disclosure
§01 / 06·Compliance posture
Honest status
What's certified, what's in flight, what's on the roadmap. No hand-waving.
01
SOC 2 Type I
In progress
Controls mapped (CC1–CC9). Auditor engagement underway.
Target: Q3 2026
02
ISO 27001
Roadmap
Statement of Applicability drafted; formal audit follows SOC 2.
Target: 2027
03
GDPR
Compliant
DPA available on request. EU data residency by default.
Target: Active
04
DORA / NIS2 / EU AI Act
Aligned
Product capabilities map to articles; control library shipped.
Target: Active
§02 / 06·Security & data handling
How customer data lives
01
EU data residency
Primary database, auth, and storage in EU (Frankfurt). No customer data leaves the EU for storage.
AI inference uses EU regions where available. US fallback models receive de-identified payloads only.
02
Encryption
TLS 1.2+ in transit. AES-256 at rest. Per-tenant row-level isolation enforced at the database layer.
Envelope encryption (AES-256-GCM, per-record DEK) live for sensitive columns. External KMS BYOK on Enterprise roadmap. Every encrypt/decrypt is audited.
03
Access control
SAML SSO, SCIM provisioning, role-based access, hash-chained audit logs with optional SIEM streaming.
Six-role hierarchy with segregation-of-duties enforced for attestations.
§03 / 06·Resilience
Recovery & continuity targets
Continuity targets and what we test against.
RTO
4 hours
Recovery Time Objective
RPO
15 minutes
Recovery Point Objective
Backups
Daily + PITR
Point-in-time recovery within 7 days
DR drill
Quarterly
Restore test against a clean region
01
Primary region
eu-central-1 · Frankfurt
All writes and reads. EU data residency by default.
02
Warm standby
eu-west-1 · Ireland
Snapshot + WAL replay. Promoted on declared regional outage. Available on Enterprise contracts.
03
Edge / API
Multi-region
Edge functions and CDN run globally; survive regional DB issues with cached responses where possible.
We don't claim active-active multi-master. We commit to a tested warm-standby promote drill within RTO. Full DR/BCP runbook is available to Enterprise customers under NDA. Email [email protected].
§04 / 06·Insurance & liability
Financial backing
01
Cyber & professional liability
Coverage placed via Xali. Policy includes cyber, technology errors & omissions, and general professional liability.
COI and policy schedule available under NDA on request.
02
Contractual commitments
Standard MSA carries a liability cap aligned to insurance limits; uncapped indemnities for confidentiality breach, IP infringement, and gross negligence (where law permits).
Enterprise contracts support custom carve-outs and named additional insureds.
§05 / 06·Subprocessors
Third-party services that may process customer data
We notify customers 30 days before adding a new subprocessor.
Subprocessor	Purpose	Region
Supabase	Primary database, auth, storage	EU (Frankfurt)
Google Cloud (Gemini)	AI inference for analysis features	EU multi-region
OpenAI	AI inference (fallback model)	US — content de-identified
Resend	Transactional email delivery	EU / US
Cloudflare	DNS, CDN, DDoS protection	Global edge
§06 / 06·Contact
Report & reach out
01
Report a vulnerability
We welcome coordinated disclosure. Scope, safe harbor, and triage SLAs are documented on our disclosure page.
Disclosure policy
02
Security & trust contact
Procurement questionnaires, SOC 2 progress, custom DPAs: [email protected]
Download DPA System status
Privacy Controls and Cookies
We (nextfluent.com) and selected third parties (2) collect personal information as specified in the privacy policy and use cookies or similar technologies for technical purposes and, with your consent, for functionality, experience and “marketing (personalized ads)” as specified in the cookie policy.
You can freely give, deny, or withdraw your consent at any time by accessing the preferences panel. Denying consent may make related features unavailable.
Use the “Accept” button to consent. Use the “Reject” button to continue without accepting.
Press again to continue 0/2