SOC 2 Type II

Enterprise security,
built in
from the start.

Your IP is your most sensitive asset. Nyotta AI is designed so that you never have to choose between AI-powered speed and the trust your customers require.

Audit statusType II
Framework
SOC 2 Type II
Criteria
Security, Availability, Confidentiality
Reports
Available under NDA
Details

Security came before the product.

We build for industrial and automotive teams whose designs, costs, and supplier data are the business. That constraint shaped the system from the first commit. Three ideas hold the whole approach together.

Per-tenant data isolation

Every customer's data is scoped to their organization and checked on every request, so one tenant never sees another's.

Humans stay in control

The system proposes and a person approves. Nothing writes back to your systems on its own.

Least access, always

People and services get the minimum they need to do their job, reviewed on a regular schedule.

Security is architectural, not just policy.

01

Encryption at rest and in transit

AES-256 encryption at rest. TLS 1.2+ for all data in transit. No plaintext storage of customer data at any layer.

02

Per-tenant data isolation

Each customer's data is scoped to their organization and enforced on every read and write, so one tenant can never reach another's. Encrypted at rest and in transit.

03

No cross-tenant model training

Your data is never used to train models for other customers. This is the single biggest concern for industrial AI buyers and it is architectural by design.

04

Human approval before any write

Nyotta AI reads continuously, but it never writes back on its own. A person reviews and approves every output before it reaches your systems. The approval gate is a deliberate safety control against autonomous action.

05

Full audit logs

Every read and write is logged with timestamps and user attribution. Required for your customers' own compliance audits. Nyotta AI supports their chain of custody.

06

SSO / SAML, MFA, and RBAC

Standard enterprise access controls. Integrate with your existing identity provider. Role-based permissions per program, per user.

How we run it day to day.

Certification proves the controls exist. This is how they show up in daily operation.

Governance

Least privilege, reviewed changes

Access follows least privilege, and no one holds standing access to production. Every production change is peer reviewed before it ships. Engineers complete security training at onboarding and annually, and personnel pass background checks where local law permits.

Third-party risk

Vendors vetted, then watched

Every sub-processor is assessed before it can touch customer data, then reviewed on an ongoing basis. We favor vendors that carry their own SOC 2 or ISO attestations.

Testing

Tested for weaknesses

Our systems undergo penetration testing to surface vulnerabilities before they can be exploited.

Incident response

A documented response plan

We keep a documented incident response plan with defined severity levels and clear on-call ownership. If a confirmed incident affects your data, we notify you within 72 hours, consistent with your DPA.

Data residency & retention

You know where your data lives

Customer data is hosted in the United States, in a US West region. It is retained for the life of your contract and deleted from production within 90 days of a verified request.

Availability & recovery

Built to stay up and recover

Encrypted backups run daily and are tested on a regular schedule, with a recovery target of 24 hours and a 99.9% uptime objective. Availability is one of the SOC 2 criteria we are audited against.

Sub-processor disclosure.

Industrial buyers need to know who sees their data. We disclose our entire sub-processor chain on request.

LLM providers
Disclosed on request
Cloud infrastructure
Disclosed on request
Vendor documentation
DPA, MSA framework, and security questionnaires (CAIQ/SIG) available

Security is never finished.

Standards confirm the work. They do not end it. We keep testing, reviewing, and tightening as we grow, and we are glad to walk your team through any of it.

Security questions?
We answer all of them.

DPA, MSA, CAIQ/SIG questionnaires, and architecture review available on request.

Contact security team