Trust Center
Built so your security team can say yes.
Everything Neivan publishes about how we protect customer data, who we share it with, and how we respond when things go wrong — collected in one place.
Compliance & certifications
SOC 2 Type II
Controls implemented and internally audited; independent audit planned. Ask us for a status update.
GDPR & UK-GDPR
Designed to align with GDPR: SCCs for EU transfers, DPA available.
CCPA
California consumer rights honored regardless of residence.
HIPAA
On our roadmap. Contact us to discuss regulated-industry requirements.
Security
Encryption
TLS 1.3 in transit · AES-256 at rest · CMEK on the Enterprise roadmap.
Access control
MFA, RBAC, separation of duties, immutable audit logs.
Incident response
Founder-led on-call with defined severity and notification process.
Vulnerability program
Static analysis and dependency scanning in CI; independent pentest planned pre-launch.
Privacy
Operations
Service status
Incident notifications go to affected customers directly. Public status page coming with GA.
Service Level Agreement
Availability targets and support commitments as we scale.
Changelog
Public release notes for every shipped change.
Acceptable Use
What customers and their AI agents may and may not do.