Security & Data Protection

Security your team will approve.

Tenant isolation, read-only defaults, scoped AI context, and a permanent audit trail. Structural from day one, not bolted on.

Security by architecture

Separate layers, separate blast radius.

When access, execution, evidence, and release are distinct control points, a compromise in one area does not automatically expose everything.

Default

Read-only by default

Connector pulls do not mutate source systems. Write-side actions are opt-in per integration and always approval-gated.

Architectural

Tenant & workspace isolation

Customer data, credentials, run outputs, and Decision History are tenant-scoped - not co-mingled with other customers.

Enterprise

Role-based access & SSO

Owner, Admin, Member, and Guest roles govern who connects integrations, runs departments, and views sensitive data.

Per run

Scoped AI context

Departments receive workstream guides and org-wide policies - not every vault in the organisation.

Always on

Encryption & credentials

TLS in transit, encrypted storage at rest, and per-tenant credential isolation. CMEK available on Enterprise.

Contractual

No public model training

Contractual opt-outs with upstream providers so your business content is not used to train shared models.

Architecture

How a governed decision flows.

From OAuth connector to immutable audit trail - every step is logged, scoped, and approval-gated.

Real scenarios

Questions your security team will ask.

CISO & IT

Can Sales AI see our payroll data?

No - unless you scope Finance integrations and wiki folders to Sales workstreams. Default boundaries and role access limit what each department receives.

Finance leadership

Finance connects NetSuite - what can Nimbus do?

Read ledger and AP data for forecasts and audits. Any write-back pauses for CFO approval. Credentials are encrypted and tenant-scoped.

Audit & compliance

Auditor requests a Q2 margin decision trail

Decision History shows the Finance run, data pulls, wiki policy version, approval timestamp, and landed report - without reconstructing from chat exports.

Scope by default

Each workstream only sees the connectors and wiki folders you attach to it.

Sales workstreamIn scope
  • HubSpot
  • Salesforce
  • Company wiki · GTM
Finance systemsNot in Sales scope
  • NetSuite
  • Payroll wiki
  • AP exports
  • Sales workstream scope. Only connected GTM systems.
  • Cross-department access. Blocked by default.
  • Write-back path. Approval gate required.
Compliance

Certifications and frameworks.

GDPR compliant today. ISO 27001 and SOC 2 Type 1 independent audits underway.

Compliant

GDPR compliant

Data protection by design. EU and UK data subject rights supported. Data processing agreement available on request.

In audit

ISO 27001 compliant - audit pending

Information security management aligned to ISO 27001. Independent certification audit in progress.

In audit

SOC 2 Type 1 compliant - audit pending

Controls aligned to SOC 2 Type 1 trust criteria. Independent audit in progress.

Certification tracker

Where each framework stands today.

GDPR

Compliant

DPA available on request. EU and UK data subject rights supported.

ISO 27001

Audit in progress

ISMS aligned to ISO 27001. Independent certification audit underway.

SOC 2 Type 1

Audit in progress

Controls mapped to trust criteria. Independent audit underway.

Decision history preview

Q2 margin decision trail

Finance workstreamApproved · CFO
  • Finance run ID
  • Source pulls
  • Wiki policy version
  • Approver + timestamp
  • Landed report

One export for auditors - no chat reconstruction required.

FAQ

Security questions.

Can Nimbus access all of our company data?

No. Nimbus only accesses data from integrations you connect and scopes you authorise. Workstreams and departments receive only the connectors and wiki folders configured for that work.

Is our data mixed with other customers' data?

No. Each organisation operates in an isolated workspace. Credentials, runs, wiki content, and Decision History are tenant-scoped.

Can AI change our systems without asking?

No. Integrations are read-only by default. Write-backs require explicit enablement and human approval through Governance.

Do you train public models on customer data?

No. Your workspace data is used to serve your organisation - not to train shared public models. We enforce contractual opt-outs with upstream AI providers.

Where is my data stored?

Standard deployment offers regional choice (US, EU, UK). Data stays in the region you select. Enterprise plans may offer dedicated infrastructure for stricter sovereignty requirements.

Who can see sensitive wiki or finance data?

You control this with roles (Owner, Admin, Member, Guest) and scoped access to workstreams, departments, and wiki folders. Guests can be limited to read-only shared material.

What encryption do you use?

TLS for data in transit. Encrypted storage for data and credentials at rest. Per-tenant credential isolation. Customer-managed keys available on Enterprise.

Can we use our existing SSO?

Yes. Enterprise plans support SAML 2.0 and OIDC with common identity providers including Okta, Azure AD, and Google Workspace.

What gets logged for audit?

Run steps, data pulls, recommendations, approvals, rejections, filesystem checkpoints, and integration activity - projected into Decision History.

Can our security team review your architecture?

Yes. Request a security review and we will share documentation, arrange a walkthrough, or provide a security pack for your assessment.

How is this different from Governance?

Security covers isolation, encryption, access, and AI data handling. Governance covers approval tiers, spend caps, policy enforcement at release time, and rollback. Both are built in.

Ready for your security team to review us?

We can walk your team through our architecture, share documentation, or arrange a dedicated assessment.