Platform
The ProblemThe Neivan ApproachHow it WorksAgent TemplatesMobile AppFAQs
Resources
SecurityDocumentationAPI Reference
AboutPricing
Sign inRequest Access
The ProblemThe Neivan ApproachHow it WorksAgent TemplatesMobile AppFAQs
SecurityDocumentationAPI Reference
AboutPricingContact SalesSign in
Legal

Security at Neivan

Effective July 22, 2026.

On this page
  • Compliance
  • Encryption
  • Access control
  • Data isolation
  • Resilience
  • Application security
  • Incident response
  • Sub-processors
  • Contact

Compliance

SOC 2 Type II — controls are implemented and internally audited; an independent audit is planned but not yet engaged. Contact [email protected] for a current status summary.

GDPR and CCPA processes in place: consent management, data subject request handling, export, and deletion. Standard Contractual Clauses available for EU data transfers.

HIPAA support and ISO 27001 certification are on our roadmap. If you operate in a regulated industry, contact us to discuss your requirements.

Encryption

In transit: TLS 1.3 with strict cipher suites. HSTS enforced on all production domains.

At rest: AES-256 encryption on managed cloud storage. Customer-managed encryption keys (CMEK) are on the Enterprise roadmap.

Secrets and integration credentials are sealed with a separate AES-256-GCM key envelope and never logged.

Access control

Customer side: role-based access control, MFA, session enforcement, and automatic lockout after repeated failed logins. SAML SSO and SCIM provisioning are on the Enterprise roadmap.

Neivan side: production access is restricted to the founding team, protected by MFA, and logged. Administrative actions in our internal console are recorded in an immutable audit trail.

Data isolation

Per-tenant logical isolation with row-level security enforced on every customer-data table at the database layer.

Customer content is never used to train shared models. Vector stores are scoped to your tenant.

Resilience

Managed cloud infrastructure with automated backups and a documented backup and restore runbook.

Full recovery drills are a gate on our launch checklist, and we will publish recovery objectives (RPO/RTO) as we finalize them.

Application security

Static analysis, dependency scanning, and tenant-isolation checks run in CI on every build. Dependency vulnerabilities are triaged to zero before release.

An independent penetration test is planned before general availability. We welcome responsible disclosure at [email protected] (PGP key on request).

Incident response

We run founder-led on-call with a defined severity process. Affected customers are notified promptly — no later than 72 hours after a confirmed incident involving their data, and usually much sooner.

Post-incident reports are shared with affected customers for any significant incident.

Sub-processors

Current sub-processors are listed in our DPA. We notify customers at least 30 days before adding a new sub-processor; you may object and terminate without penalty if you do not consent.

Contact

Disclose a vulnerability: [email protected] (PGP available). Compliance questionnaires: [email protected]. Customer security reviews: your account team or [email protected].

See also:Privacy PolicyTerms of ServiceSecurityContact us

The intelligence layer for what's next — built for teams who want AI that remembers, coordinates, and improves.

Platform
  • Agent Network
  • Memory & Knowledge
  • Workflows
  • Decision Engine
  • Security
  • Pricing
Trust
  • Trust Center
  • Security
  • Privacy
  • DPA
  • Sub-processors
Company
  • About
  • Docs
  • Help & Support
  • Contact
  • Careers
  • Changelog
Private preview··Your privacy rights·Acceptable Use
© 2026 Neivan, Inc. — All rights reserved.
Privacy·Terms·SLA·Cookies