Can Sales AI see our payroll data?
No - unless you scope Finance integrations and wiki folders to Sales workstreams. Default boundaries and role access limit what each department receives.
Tenant isolation, read-only defaults, scoped AI context, and a permanent audit trail. Structural from day one, not bolted on.
When access, execution, evidence, and release are distinct control points, a compromise in one area does not automatically expose everything.
Connector pulls do not mutate source systems. Write-side actions are opt-in per integration and always approval-gated.
Customer data, credentials, run outputs, and Decision History are tenant-scoped - not co-mingled with other customers.
Owner, Admin, Member, and Guest roles govern who connects integrations, runs departments, and views sensitive data.
Departments receive workstream guides and org-wide policies - not every vault in the organisation.
TLS in transit, encrypted storage at rest, and per-tenant credential isolation. CMEK available on Enterprise.
Contractual opt-outs with upstream providers so your business content is not used to train shared models.
From OAuth connector to immutable audit trail - every step is logged, scoped, and approval-gated.
No - unless you scope Finance integrations and wiki folders to Sales workstreams. Default boundaries and role access limit what each department receives.
Read ledger and AP data for forecasts and audits. Any write-back pauses for CFO approval. Credentials are encrypted and tenant-scoped.
Decision History shows the Finance run, data pulls, wiki policy version, approval timestamp, and landed report - without reconstructing from chat exports.
Scope by default
Each workstream only sees the connectors and wiki folders you attach to it.
GDPR compliant today. ISO 27001 and SOC 2 Type 1 independent audits underway.
Data protection by design. EU and UK data subject rights supported. Data processing agreement available on request.
Information security management aligned to ISO 27001. Independent certification audit in progress.
Controls aligned to SOC 2 Type 1 trust criteria. Independent audit in progress.
Certification tracker
Where each framework stands today.
DPA available on request. EU and UK data subject rights supported.
ISMS aligned to ISO 27001. Independent certification audit underway.
Controls mapped to trust criteria. Independent audit underway.
Decision history preview
Q2 margin decision trail
One export for auditors - no chat reconstruction required.
No. Nimbus only accesses data from integrations you connect and scopes you authorise. Workstreams and departments receive only the connectors and wiki folders configured for that work.
No. Each organisation operates in an isolated workspace. Credentials, runs, wiki content, and Decision History are tenant-scoped.
No. Integrations are read-only by default. Write-backs require explicit enablement and human approval through Governance.
No. Your workspace data is used to serve your organisation - not to train shared public models. We enforce contractual opt-outs with upstream AI providers.
Standard deployment offers regional choice (US, EU, UK). Data stays in the region you select. Enterprise plans may offer dedicated infrastructure for stricter sovereignty requirements.
You control this with roles (Owner, Admin, Member, Guest) and scoped access to workstreams, departments, and wiki folders. Guests can be limited to read-only shared material.
TLS for data in transit. Encrypted storage for data and credentials at rest. Per-tenant credential isolation. Customer-managed keys available on Enterprise.
Yes. Enterprise plans support SAML 2.0 and OIDC with common identity providers including Okta, Azure AD, and Google Workspace.
Run steps, data pulls, recommendations, approvals, rejections, filesystem checkpoints, and integration activity - projected into Decision History.
Yes. Request a security review and we will share documentation, arrange a walkthrough, or provide a security pack for your assessment.
Security covers isolation, encryption, access, and AI data handling. Governance covers approval tiers, spend caps, policy enforcement at release time, and rollback. Both are built in.
We can walk your team through our architecture, share documentation, or arrange a dedicated assessment.