Trust Centre

Enterprise-grade security, built in from day one.

NESTSIGNAL is a multi-tenant SaaS platform. Every organisation operates inside its own isolated workspace, and access to that workspace is granted only through explicit permissions or auditable delegation. This page is maintained by NESTSIGNAL and summarises the controls visible to customers today.

Security

Defence-in-depth: workspace isolation, least-privilege role-based access, encrypted transport and storage, secrets kept server-side, and continuous audit logging of sensitive actions.

Privacy

Customer data belongs to the customer. NESTSIGNAL does not sell customer data and does not use customer data to train shared AI models.

Compliance

Designed against SOC 2, ISO 27001 and GDPR control objectives. Specific certifications are listed under Roadmap once attained.

RBAC

Owner, Administrator, Manager, Operator, Member, Viewer and Client roles, with per-permission overrides per workspace. Every permission is resolved through a single Identity & Access service.

Delegated Access

Internal employees, fractional executives, certified delivery partners, agencies and external consultants all use one delegation framework with owner approval, recorded consent, defined scope and expiry. Every action is audited.

Data Isolation

Every workspace is a logical security boundary. Database queries are scoped by workspace ID and protected by row-level security. AI agents, knowledge bases, embeddings and chat history are scoped to the active workspace.

Encryption

Data in transit is protected with TLS. Data at rest is encrypted by the hosting platform. OAuth tokens, API keys and webhook secrets are stored server-side and never exposed to the browser.

Audit Logging

Logins, permission changes, AI actions, exports, integration changes, and delegated-access grants and uses are timestamped and queryable by workspace owners.

AI Governance

Per-workspace controls for human-approval requirement, autonomy level, allowed knowledge sources, allowed tools, and max actions per run. AI execution refuses to run without a workspace context.

Availability

NESTSIGNAL runs on managed cloud infrastructure with redundant compute and storage. Live status is published below.

Roadmap

SSO with Microsoft Azure AD/Entra ID, Google Workspace and Okta. SCIM provisioning. Customer-managed encryption keys. Regional data residency options.

Future Certifications

SOC 2 Type I — planned. ISO 27001 — roadmap. GDPR — operational alignment today; full Data Processing Addendum on request.

Subprocessors

Hosting and database: Lovable Cloud (Supabase). Authentication: Lovable Cloud. AI inference: Lovable AI Gateway. Customer-connected integrations (e.g. Google Search Console, Google Analytics 4) are subprocessors only for that customer's workspace.

Status

Service status, incident history and planned maintenance will be published at status.nestsignal.ai. In the interim, contact security@nestsignal.ai for incident updates.

Security Contact

Report vulnerabilities or security concerns to security@nestsignal.ai. We acknowledge reports within one business day. Please include reproduction steps; do not include customer data in your report.

Data Processing & DPA

A Data Processing Addendum is available on request for customers in regulated industries or with GDPR obligations.

API Security

API keys are scoped to a workspace, revocable, and recorded in the audit trail when used. Server endpoints validate input, authorise the caller through the IAM service, and write audit events on mutation.

Shared responsibility

NESTSIGNAL provides the platform controls listed above. Workspace owners are responsible for who they invite, the roles they assign, the integrations they connect, and whether they enable Managed Services, Operating Partner or Delivery Partner access. Customer data belongs to the customer.

Reporting a security issue

Please email security@nestsignal.ai with details and reproduction steps. We acknowledge reports within one business day.

This page describes current platform capabilities and is not a certification. Specific compliance attestations will be listed under "Future Certifications" once attained.

← Back to nestsignal.ai