Security
Defence-in-depth: workspace isolation, least-privilege role-based access, encrypted transport and storage, secrets kept server-side, and continuous audit logging of sensitive actions.
Trust Centre
NESTSIGNAL is a multi-tenant SaaS platform. Every organisation operates inside its own isolated workspace, and access to that workspace is granted only through explicit permissions or auditable delegation. This page is maintained by NESTSIGNAL and summarises the controls visible to customers today.
Defence-in-depth: workspace isolation, least-privilege role-based access, encrypted transport and storage, secrets kept server-side, and continuous audit logging of sensitive actions.
Customer data belongs to the customer. NESTSIGNAL does not sell customer data and does not use customer data to train shared AI models.
Designed against SOC 2, ISO 27001 and GDPR control objectives. Specific certifications are listed under Roadmap once attained.
Owner, Administrator, Manager, Operator, Member, Viewer and Client roles, with per-permission overrides per workspace. Every permission is resolved through a single Identity & Access service.
Internal employees, fractional executives, certified delivery partners, agencies and external consultants all use one delegation framework with owner approval, recorded consent, defined scope and expiry. Every action is audited.
Every workspace is a logical security boundary. Database queries are scoped by workspace ID and protected by row-level security. AI agents, knowledge bases, embeddings and chat history are scoped to the active workspace.
Data in transit is protected with TLS. Data at rest is encrypted by the hosting platform. OAuth tokens, API keys and webhook secrets are stored server-side and never exposed to the browser.
Logins, permission changes, AI actions, exports, integration changes, and delegated-access grants and uses are timestamped and queryable by workspace owners.
Per-workspace controls for human-approval requirement, autonomy level, allowed knowledge sources, allowed tools, and max actions per run. AI execution refuses to run without a workspace context.
NESTSIGNAL runs on managed cloud infrastructure with redundant compute and storage. Live status is published below.
SSO with Microsoft Azure AD/Entra ID, Google Workspace and Okta. SCIM provisioning. Customer-managed encryption keys. Regional data residency options.
SOC 2 Type I — planned. ISO 27001 — roadmap. GDPR — operational alignment today; full Data Processing Addendum on request.
Hosting and database: Lovable Cloud (Supabase). Authentication: Lovable Cloud. AI inference: Lovable AI Gateway. Customer-connected integrations (e.g. Google Search Console, Google Analytics 4) are subprocessors only for that customer's workspace.
Service status, incident history and planned maintenance will be published at status.nestsignal.ai. In the interim, contact security@nestsignal.ai for incident updates.
Report vulnerabilities or security concerns to security@nestsignal.ai. We acknowledge reports within one business day. Please include reproduction steps; do not include customer data in your report.
A Data Processing Addendum is available on request for customers in regulated industries or with GDPR obligations.
API keys are scoped to a workspace, revocable, and recorded in the audit trail when used. Server endpoints validate input, authorise the caller through the IAM service, and write audit events on mutation.
NESTSIGNAL provides the platform controls listed above. Workspace owners are responsible for who they invite, the roles they assign, the integrations they connect, and whether they enable Managed Services, Operating Partner or Delivery Partner access. Customer data belongs to the customer.
Please email security@nestsignal.ai with details and reproduction steps. We acknowledge reports within one business day.
This page describes current platform capabilities and is not a certification. Specific compliance attestations will be listed under "Future Certifications" once attained.