A pale blue scene: a frosted glass shield floating over flowing silk, with the GDPR, ISO 27001, SOC 2 and EU AI Act marks set into glass medallions beneath it.
Trust · Security & compliance

Security first.
By architecture.

It comes before everything else, and it is built in, never bolted on: your own instance and your own database, access enforced inside every query, an audit chain that proves itself. Everything on this page is a shipped mechanism, and the trust library puts it in writing, readable right here.

One client. One deployment. One boundary.

There is no shared platform. Each client runs their own instance with their own database; documents, conversations, permissions and audit records never share storage with anyone else's.

Isolation is the deployment model

Single-tenant per client, by decision, not a configuration option; there is no multi-tenant mode to misconfigure.

One database holds all state

One PostgreSQL carries the index, conversations, audit log and job queue: one backup scope, one encryption scope, one data map.

Credentials are write-only

Connector and channel secrets are accepted, used, and never displayed again.

Every webhook proves itself

Each platform's own signature scheme is verified before any processing; unverified calls are rejected.

An EU data centre, or your own servers

Under our management in the EU, or self-hosted on your own Linux server, the same product either way.

A row of server racks in a data centre. Fibre connections plugged into a server. A wall of individually keyed lockboxes. A red wax seal closing an envelope. The EU flag set into a glass building front.
The AI boundary

What leaves, and what never does.

Indexing runs entirely inside your deployment, always. Self-hosted, answers stay home too, on your own hardware. On the Naxis AI service, only the question and the permission-filtered excerpts travel: zero retention, no training, in writing, and no AI keys on the instance at all.

The safety record, in writing
A dashed deployment boundary holding sources and the index; one wire leaves it carrying the question and permitted excerpts to the Naxis AI disc, one returns with the answer, nothing retained.
Access & audit

Permissions inside every query. A record that proves itself.

The group filter lives inside every database query the assistant makes, on every channel and API; no surface runs above it. And every consequential event lands in an append-only log where each entry carries the hash of the one before — nothing edits, nothing deletes, verification is one click.

How permissions work
A question passing through the reader’s-groups ring before reaching documents, one source dimmed outside their groups; beside it, the audit chain — question, permission change, erasure, sign-in — linked entry to entry.
The pipeline

Security as a pipeline, not a promise.

One pipeline gates every release: static checks, the full suite, a signed, sealed artifact, and a failed health check rolls itself back. Another watches the fleet continuously — edge defence, throttled sign-ins, signed heartbeats, short-lived leases. Managed and self-hosted install the identical, verified artifact.

Request the architecture record
The release rail — static gates, the suite, the sealed signed artifact, staged install, self-rollback — over the fleet band: signed heartbeats and short-lived leases pulsing continuously.
GDPR & EU AI Act

Rights with a mechanism behind them.

Export is self-service, erasure is deletion — store and index alike, no tombstones — and each deployment generates its Article 30 record from live configuration. Under the EU AI Act the assistant declares itself on every surface, and high-risk uses are contractually excluded: the position, article by article.

The GDPR mapping, article by article
A person at the centre: their export leaving as one file, a document dissolving to nothing on erasure, the ‘You are talking with AI’ disclosure, and records of processing generated from live configuration.
Frameworks

Frameworks, with their status on the plate.

GDPR and the EU AI Act are built into the product; the control themes ISO 27001 and SOC 2 expect are shipped mechanisms today. Each framework keeps a status page that answers plainly, station by station — nothing is claimed before it is held; the SOC 2 page carries its current status.

The ISO 27001 track
Four framework plates hanging from the product mark — GDPR, ISO 27001, SOC 2 and the EU AI Act — each with its status spoken plainly: built-in or shipped.
In writing

In writing, on request.

The architecture record, the data-processing agreement, the answered security questionnaire: file a standing request from your account and each lands on your own thread the day it exists. Answers come from the architecture, never a script.

Open the document desk
Three records — the architecture record, the data-processing agreement, the security questionnaire — wired to the account desk, landing with the reviewer on their own thread.

Read it here.

The documents reviewers ask for, frameworks, legal structure, technical record, readable on this page, no request forms in the way. Signed copies are an account request away.

Certifications & frameworks Read it here

GDPR: how a deployment complies

The rights articles as product mechanisms: export, erasure, records of processing, each one built in, none of it paperwork after the fact.

Every Naxis deployment is a single-tenant system processing only the client's own documents, on infrastructure the client chooses. GDPR compliance is implemented as product mechanisms, not policies:

Art. 15 · access
Self-service "Export my data" for every signed-in person (JSON, complete), plus an administrator subject-access export for any subject the deployment knows.
Art. 17 · erasure
Hard delete, everywhere: a person's conversations, or a single document, are removed from the store and the search index in one action. Erasure is itself recorded in the audit log; no tombstone data remains.
Art. 28 · processing
Each deployment is contracted under a Data Processing Agreement including the sub-processor notice procedure (see Legal documents below).
Art. 30 · records
The deployment generates its own record-of-processing manifest from the configuration that actually runs (retention values, sub-processors, technical measures), so the paperwork cannot drift from reality.
Retention
Conversation and audit retention are explicit, configurable values enforced by a nightly job; the live values are shown read-only in the admin console.

The generated manifest for a specific deployment is available to its administrator at any time; a sample is in Technical documentation below.

Request to see

An account action, the request files under your Naxis account, and the answer arrives on its thread.

Certifications & frameworks Read it here

EU AI Act: position & measures

Transparency by construction: AI-interaction disclosure on every surface, an AI-literacy resource in the product, high-risk uses contractually excluded.

Article 50
Every conversational surface (web chat, sign-in, invitations, messaging channels) discloses that answers are AI-generated and cited.
Article 4
The in-product help centre serves as the deployer's AI-literacy resource: how answers are produced, what citations mean, what the assistant refuses and why.
Annex III
Deployments are contractually excluded from high-risk uses; the product is a knowledge engine over business documents, and the terms keep it that.
Human oversight
Answers cite their sources or decline. Nothing executes actions; a human reads, verifies against the cited passage, and decides.
Certifications & frameworks Read it here

ISO/IEC 27001

The control themes the standard expects, access control, cryptography, operations security, supplier relationships, are shipped mechanisms described in Technical documentation.

The system is built and operated in line with what the standard asks of an information-security management system; the certification itself is what we are waiting on. The control themes, as the mechanisms that ship in every deployment:

Access control
Group-based permissions settled before anything is found; accounts activate by invitation link, and administrators never see or set a password.
Cryptography
TLS in transit; connector and channel secrets are write-only after entry, used for syncing and redacted from every API response.
Operations security
Versioned releases installed in a quiet window after a safety backup, rolling back on their own if the health check fails; retention enforced by a nightly job that logs its own runs.
Logging & monitoring
Every consequential event lands on an append-only, hash-chained audit log; verification recomputes the whole chain on demand.
Supplier relationships
At most two sub-processor categories, each under a written DPA; the fullest configuration, self-hosted with self-hosted AI, has none.

Its own page carries the current status. File a standing request from your account, and security questionnaires are answered directly from the architecture in the meantime.

Request it when ready

An account action, the request files under your Naxis account, and the answer arrives on its thread.

Certifications & frameworks Read it here

SOC 2 Type II

The trust criteria, security, availability, confidentiality, privacy, run as engineered product mechanisms; the SOC 2 page carries the current status.

The system operates to the trust services criteria as engineered mechanisms, evidenced on its own audit chain; the report itself is what we are waiting on. Criterion by criterion:

Security
Single-tenant isolation per client, signature-verified webhooks, write-only credentials and rate-limited, challenge-backed sign-in surfaces.
Availability
Health-checked releases that roll back on their own if an update fails, behind a safety backup taken first.
Confidentiality
Permission settled before anything is found, and an AI boundary under zero-retention terms; the model never sees documents the asking person cannot see.
Privacy
GDPR rights as product mechanisms: self-service export, hard-delete erasure including the index, a generated record of processing.

Its own page carries the current status. File a standing request from your account, and security questionnaires are answered directly from the architecture in the meantime.

Request it when ready

An account action, the request files under your Naxis account, and the answer arrives on its thread.

Legal documents Read it here

Data Processing Agreement (Art. 28)

The DPA every deployment is contracted under, subject matter, duration, sub-processor notice procedure, audit rights, deletion on termination.

The signed DPA is executed per client. Its structure, so your legal team knows what to expect:

  • Subject matter & duration, processing of the client's business documents for the sole purpose of answering the client's own users; runs with the service agreement.
  • Nature & purpose, indexing and answering with citations; no secondary use, no training on client data.
  • Sub-processors, listed by category with a written notice procedure before any change (see the sub-processor notice below).
  • Security measures, the technical and organisational measures, referencing the deployment's own generated manifest so the annex matches the running configuration.
  • Deletion, on termination, the deployment and its data are destroyed or handed over; self-hosted clients hold the data throughout.
  • Audit, information and audit rights, with the audit log and manifest as first-class evidence.

Request the full template, or a signed copy for review under NDA, through the contact page; it is provided as a matter of course.

Request to see

An account action, the request files under your Naxis account, and the answer arrives on its thread.

Legal documents Read it here

Sub-processor notice

At most two categories exist, and the fullest configuration, self-hosted with self-hosted AI, has none.

AI generation
The primary configuration keeps generation in-house: a self-hosted deployment that answers entirely on its own hardware has no AI sub-processor at all. Deployments using the Naxis AI service instead send the question and the permission-filtered excerpts under a data-processing agreement with zero-retention terms: nothing is stored after the answer returns, nothing trains any model, and no client identity accompanies the request.
Hosting
Managed deployments run on an EU data-centre provider under their DPA; the instance, its database and its documents live on a server dedicated to that client. Self-hosted deployments have no hosting sub-processor at all, the client's own infrastructure carries everything.

Changes to either category follow the DPA's written notice procedure. There are no analytics, advertising or telemetry processors, the product ships none.

Request to see

An account action, the request files under your Naxis account, and the answer arrives on its thread.

Technical documentation Read it here

Security & architecture overview

One client, one deployment, one boundary, what that means concretely: containers, database, credentials, the AI boundary and the audit chain.

Tenancy

Each client runs their own complete instance: application, worker, database and document store in isolated containers on a machine that serves no other client. There is no shared platform, no pooled database, no cross-tenant anything, isolation is the deployment model, not a configuration option.

Data at rest

Store
One PostgreSQL database per deployment: documents, search index, conversations, audit log, job queue.
Credentials
Connector and channel secrets are write-only after entry: accepted, used for syncing, never displayed again, and redacted from every API response.
Webhooks
Every messaging platform's signature scheme is verified; unsigned or mis-signed calls are rejected before any processing.

The AI boundary

Indexing (reading and preparing documents for search) runs entirely inside the deployment. Generation follows the deployment's configuration: the fullest posture is a self-hosted deployment that answers entirely on its own hardware, where nothing leaves the boundary at all. Deployments using the Naxis AI service send the question and the permission-filtered excerpts (zero-retention terms, see sub-processors); the model never sees documents the asking person cannot see, because permission filtering happens before the request leaves.

In every configuration: your data is not used to train models, and nothing is retained after the answer returns.

Permissions

Access is group-based and settled before a question is even considered, everywhere the assistant answers, never in any one surface. Accounts activate by invitation link; administrators never see or set a password. Channel guests receive nothing until groups are explicitly opened to them.

The audit chain

Every consequential event, questions, answers with their citations, administrative actions, syncs, erasures, lands on an append-only, hash-chained log. Verification recomputes the whole chain on demand from the console; a broken link is impossible to hide. Rows cannot be edited or deleted; retention prunes whole aged spans and records that it did.

Updates

Releases are versioned images; deployments install them in a quiet window after a safety backup and roll back on their own if the health check fails. What changed in each release is shown in the console in plain language.

Request to see

An account action, the request files under your Naxis account, and the answer arrives on its thread.

Technical documentation Read it here

Data flow & residency

What leaves the deployment, what never does, and where things physically live.

Never leaves
Documents at rest, the search index, conversation history, the audit log, user accounts and permissions.
Leaves per answer
With self-hosted AI: nothing. With the Naxis AI service: the question plus the permission-filtered excerpts needed to answer it, under zero-retention terms. Nothing else, no identifiers.
Residency
Managed hosting runs in EU data centres. Self-hosted deployments run wherever the client puts them, the product has no home-calling dependencies for its core function.
This website
Loads no third-party scripts; visit measurement is a first-party server log described in the privacy notice, with two first-party cookies only: the strictly-necessary account session and a random visit-measurement identifier. The product itself sets exactly one strictly-necessary session cookie. The interactive demo records usage under an explicit opt-in (see the privacy notice).
Request to see

An account action, the request files under your Naxis account, and the answer arrives on its thread.

Technical documentation Read it here

Compliance manifest (sample)

Every deployment renders one of these from its own live configuration, this is the shape of it.

Generated, not written: the values below come from a deployment's actual configuration at generation time.

Deployment
client-name · single-tenant · region as contracted
Data categories
Business documents from connected sources; user accounts (name, email); conversation history; audit events
Retention
Conversations: 90 days (configurable) · audit log: 730 days (configurable) · both pruned nightly, prune runs logged
Sub-processors
None (self-hosted AI), or the Naxis AI service (zero-retention DPA) · hosting provider, or none when self-hosted
Rights handling
Art. 15 export: self-service + admin · Art. 17 erasure: hard delete incl. index · Art. 30: this manifest
Technical measures
Isolated containers · TLS in transit · hash-chained audit log · write-only credentials · signature-verified webhooks

Administrators export the real manifest for their deployment from the console at any time.

Request to see

An account action, the request files under your Naxis account, and the answer arrives on its thread.

Need something that isn't here yet? Name it from your account or ask directly, security questionnaires are answered from the architecture, not a script.

What reviewers ask first

Is Naxis Assistant GDPR-compliant?

Compliance is implemented as product mechanisms, not policies: self-service data export (Art. 15/20), hard-delete erasure that removes records from store and index alike (Art. 17), a DPA with a sub-processor notice procedure (Art. 28), and a record-of-processing manifest each deployment generates from its own live configuration (Art. 30). The details are readable in the trust library on this page.

Where is our data stored, and who can see it?

Each client runs a single-tenant deployment, own instance, own database, in an EU data centre under our management, or on your own servers. Documents at rest, the index, conversations and the audit log never leave the deployment. Nobody at Naxis reads inside your instance without a consent you grant per support ticket.

Does our data train AI models?

No, in any configuration. The fullest posture keeps everything home: a self-hosted deployment that answers entirely on your own hardware, where nothing leaves your boundary at all. Deployments that use the Naxis AI service instead send only the question and the permission-filtered excerpts, nothing is retained after the answer returns and nothing trains any model, in writing, under zero-retention terms.

Are you ISO 27001 certified or SOC 2 audited?

The control work behind both standards is shipped and reviewable on this page, and each keeps its own status page that answers this plainly, station by station. Nothing is claimed before it is held; file a standing request from your account and each artifact reaches you the day it exists.

Will you answer our security questionnaire?

Yes, from the architecture, not a script. File it as a document request from your account (or send it through the contact page) and the answers come back on your own thread.

Double productivity now

Live demo

Notes from the build.

30 Jul 2026 · 8 min read

Shadow AI: your people are asking someone else about your company

Every paste into a consumer chatbot is a question your own systems could not answer fast enough. Security vendors sell detection, which reads the app and never the question. What the 2026 breach data actually shows, how far Microsoft's new Shadow AI controls really reach, and why the only fix that scales is making the company answerable.

25 Jul 2026 · 8 min read

Naxis vs Glean: enterprise platform or private knowledge engine?

Glean is Google for your company: it finds where things are stored. Naxis is the private knowledge engine that knows what is actually true right now. Different machines, different questions, different prices. An honest way to choose, and the Glean alternative for companies of 5 to 200 people.

All posts →