Enterprise security,
built in
from the start.
Your IP is your most sensitive asset. Nyotta AI is designed so that you never have to choose between AI-powered speed and the trust your customers require.
- Framework
- SOC 2 Type II
- Criteria
- Security, Availability, Confidentiality
- Reports
- Available under NDA
Security came before the product.
We build for industrial and automotive teams whose designs, costs, and supplier data are the business. That constraint shaped the system from the first commit. Three ideas hold the whole approach together.
Per-tenant data isolation
Every customer's data is scoped to their organization and checked on every request, so one tenant never sees another's.
Humans stay in control
The system proposes and a person approves. Nothing writes back to your systems on its own.
Least access, always
People and services get the minimum they need to do their job, reviewed on a regular schedule.
Security is architectural, not just policy.
Encryption at rest and in transit
AES-256 encryption at rest. TLS 1.2+ for all data in transit. No plaintext storage of customer data at any layer.
Per-tenant data isolation
Each customer's data is scoped to their organization and enforced on every read and write, so one tenant can never reach another's. Encrypted at rest and in transit.
No cross-tenant model training
Your data is never used to train models for other customers. This is the single biggest concern for industrial AI buyers and it is architectural by design.
Human approval before any write
Nyotta AI reads continuously, but it never writes back on its own. A person reviews and approves every output before it reaches your systems. The approval gate is a deliberate safety control against autonomous action.
Full audit logs
Every read and write is logged with timestamps and user attribution. Required for your customers' own compliance audits. Nyotta AI supports their chain of custody.
SSO / SAML, MFA, and RBAC
Standard enterprise access controls. Integrate with your existing identity provider. Role-based permissions per program, per user.
How we run it day to day.
Certification proves the controls exist. This is how they show up in daily operation.
Least privilege, reviewed changes
Access follows least privilege, and no one holds standing access to production. Every production change is peer reviewed before it ships. Engineers complete security training at onboarding and annually, and personnel pass background checks where local law permits.
Vendors vetted, then watched
Every sub-processor is assessed before it can touch customer data, then reviewed on an ongoing basis. We favor vendors that carry their own SOC 2 or ISO attestations.
Tested for weaknesses
Our systems undergo penetration testing to surface vulnerabilities before they can be exploited.
A documented response plan
We keep a documented incident response plan with defined severity levels and clear on-call ownership. If a confirmed incident affects your data, we notify you within 72 hours, consistent with your DPA.
You know where your data lives
Customer data is hosted in the United States, in a US West region. It is retained for the life of your contract and deleted from production within 90 days of a verified request.
Built to stay up and recover
Encrypted backups run daily and are tested on a regular schedule, with a recovery target of 24 hours and a 99.9% uptime objective. Availability is one of the SOC 2 criteria we are audited against.
Sub-processor disclosure.
Industrial buyers need to know who sees their data. We disclose our entire sub-processor chain on request.
- LLM providers
- Disclosed on request
- Cloud infrastructure
- Disclosed on request
- Vendor documentation
- DPA, MSA framework, and security questionnaires (CAIQ/SIG) available
Security is never finished.
Standards confirm the work. They do not end it. We keep testing, reviewing, and tightening as we grow, and we are glad to walk your team through any of it.
Security questions?
We answer all of them.
DPA, MSA, CAIQ/SIG questionnaires, and architecture review available on request.