Third Party Index

Snapshot 49139

Document
Security page
URL
https://www.nexadata.com/security
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
30033 bytes
SHA-256 (raw)
f98cd7c2937d073c1674960ec5db719e7826caf61e5eb5407351af949d2a8130
SHA-256 (normalized text)
5ac230043eb44f9e6339d76957743567ef3046b86c4e1b6af156d143d84f2b76

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Security
Your data stays yours. End to end.
Nexadata pairs AI-assisted reasoning with deterministic execution, so raw customer data never reaches a language model and never leaves the platform boundary. Zero data retention, SOC 2 Type II, and enterprise access controls come standard.
SOC 2 Type II Zero Data Retention SSO / SAML / RBAC
Visit the Trust Center Talk to Security
How your data is handled
The model reasons about intent. It never touches your data.
You describe what you want in plain language. Only abstracted, structured context ever reaches the language model, and it can be anonymized. Every byte of raw data is ingested, transformed, and executed inside the Nexadata platform, deterministically, within your boundary.
Inside the Nexadata platform
Raw records
Transformations
Mappings
Ingestion, transformation, and execution all happen here, with native deterministic primitives. Raw customer data never leaves this boundary.
Abstracted context only
Reasoning model
Anthropic Claude
Reasons about intent and proposes a plan. It never processes raw data and execution never requires token usage.
Zero data retention
Four independent layers of retention control
Choose the control that fits your policy, or combine them. Each layer stands on its own, so nothing about your prompts or context has to persist anywhere you do not want it to.
01 At the platform
ZDR mode
A configurable setting that keeps AI prompts and metadata out of persistent storage. Context is used in flight, then discarded.
02 At the infrastructure
ZDR via Amazon Bedrock
Claude inference routes through Amazon Bedrock, which does not store prompts or completions. Per request, with no separate enterprise contract to negotiate.
03 Your key, your terms
Bring your own key
Use your own Anthropic Claude API key, applied across your tenant. Usage is governed by your direct relationship with Anthropic.
04 At the document
Textract opt-out
PDF text and table extraction runs on Amazon Textract, which is document analysis and not a language model. Nexadata runs with the AWS AI services opt-out applied, so documents are permanently deleted immediately after processing, no copy of the output is retained, and nothing is used to improve AWS models.
Compliance and governance
Enterprise controls, built in
The certifications, access controls, and audit trails your security team expects, with a human approving every change before it touches your data.
SOC 2 Type II
Independently audited controls for security, availability, and confidentiality. The full report lives in our Trust Center.
SSO and SAML
Single sign-on with SAML and OAuth2, so access follows the identity provider and policies you already run.
Role-based access control
RBAC scopes what each user can see and do, down to the workspace and the workflow.
Human in the loop
Every transformation and mapping is proposed for review. Nothing runs against your data until a person approves it.
Mapping-group audit
Nexadata records who changed a mapping group, what changed, how, and when, with version revert on mapping rules. Mapping groups carry the business logic you most need to govern, so that is exactly where the audit trail lives.
Deterministic execution
All processing uses native, repeatable platform primitives. The same inputs always produce the same trusted output.
Technical foundation
A platform engineered to keep data under your control
Cloud-agnostic
Deployable on AWS, Azure, or GCP. Currently hosted on AWS.
Monolithic and containerized
A single, tightly integrated containerized service, not a sprawl of loosely coupled parts.
Multi-tenant SaaS
A modern multi-tenant platform with isolation and access controls built in.
Public and private REST APIs
Documented REST APIs for extensibility and integration into your own stack.
See the controls for yourself
Our Trust Center has the live status of every control, certification, and policy. Have a specific requirement? Talk to our security team.
Visit the Trust Center Talk to Security