Security and compliance
What we do with your data, written down.
This page is the answer to the security questionnaire before you send it. It describes how NXTVIS handles access, data, infrastructure and incidents on every engagement, what we sign, what we have certified and what we have not yet. If something you need is missing, ask. We would rather be judged on the detail.
Controls
How every engagement is run.
These are commitments rather than aspirations: each one is written into the engagement documents, not only onto this page.
Access
Named engineers, least-privilege credentials, scoped to the systems the work needs and revoked at handover. Access is logged on your side and ours. The audit is read-only, and read-only is genuinely read-only.
Encryption
TLS in transit everywhere. Encryption at rest on every store we provision, using the cloud provider's managed keys or yours. No production data on engineer laptops; work happens inside your environment or a provisioned workspace in your region.
Residency
Hosting region (EU, UK, Gulf, US, Australia or on-premise) is chosen by your requirement. Prompts, logs and telemetry stay in the same region as the data they describe. Camera footage and biometric templates stay on site by default.
Retention
Logs, prompts and traces carry a retention schedule from day one, debugging convenience is not a reason to keep personal data indefinitely. Audit samples are deleted on report delivery unless you ask us to keep them.
Incidents
A named contact, a written response procedure, and notification to you without undue delay and within the window your DPA or BAA requires. We would rather over-report than be found quiet.
Sub-processors
A named list in the DPA (cloud provider, model API if one is used, monitoring) with notice before any change. No third-party model API touches your data without it being in that list.
What we sign
Templates ready before the first brief.
Ask for any of these from the contact page and they arrive without a sales call. We will sign your paper instead if you prefer.
Mutual NDA
With non-solicitation in both directions, surviving the engagement.
GDPR Article 28 data processing agreement
With Standard Contractual Clauses and a transfer impact assessment where personal data leaves the EEA or UK; UK IDTA or Addendum for UK controllers.
HIPAA Business Associate Agreement
For US healthcare engagements involving protected health information.
IP assignment
Code, models, documentation and infrastructure configuration assigned to you on final payment. Nothing licensed back.
Security questionnaire
Completed in your format (SIG Lite, CAIQ or your own) before any bid.
Company registration and insurance
Provided on request, before a bid rather than after it.
Certifications
What we hold, and what we are working towards.
We would rather tell you plainly than let you discover it in due diligence.
In place today
- Written information-security policy covering access, devices, data handling and incidents
- Published controls (this page) and completed security questionnaires on request
- GDPR processor documentation: Article 28 DPA, SCCs, sub-processor list, records of processing
- HIPAA BAA for US healthcare work
- On-premise and in-region deployment patterns used on live systems
In progress
- ISO/IEC 27001 certification: ask for the current stage and target date
- SOC 2 Type II: scoped; ask for the current status
- Third-party penetration testing of our own delivery infrastructure, on a scheduled cycle
AI governance
What ships with every model.
Documentation is part of the deployment, not an extra. These are the artefacts a regulator, an auditor or your own risk team can ask for, and they arrive with the system.
Model card
What the model does, what it was trained and evaluated on, its known limits, and the fallback behaviour when it is unsure.
Data lineage and flow map
Where data is collected, stored, processed, backed up and accessed, including regions, vendors and sub-processors.
Risk classification
An EU AI Act risk classification and a DPIA-style review for every proposed workflow, in the audit report, before anything is built.
Human oversight and transparency
Approval gates where a decision carries risk, AI disclosure where a person interacts with a system, and marking of generated content.
Monitoring and drift
Accuracy, drift and usage monitoring from launch, with retraining triggers written down and a dashboard your team owns.
Handover
Documentation, runbooks and training so you can operate the system without us. Success is when you stop needing us for the thing we built.
Questions
Send us the questionnaire.
Security reviews are faster when they start with the documents. Ask for the DPA, the NDA, the sub-processor list or a completed questionnaire in your format, and an engineer (not a sales team) will send them within a working day.
We reply within one working day.