Skip to content

Security

Built into your estate. Control stays yours.

NEXA Forward does not sit beside the information system. It integrates by keeping identity, entitlements, technical access and secrets strictly apart.

This page states control principles and mechanisms. Technologies, settings and client environments are covered in a scoping workshop, under a confidentiality agreement.

Policy enforced

  • Identity
  • Entitlements
  • Technical access
  • Secrets

Four separations, one policy

No user, process or agent reaches a data source directly. Everything goes through a single entry point that enforces policy.

  • Identity

    Authentication is delegated to your enterprise directory. The platform stores no user passwords.

  • Entitlements

    Once identity is validated, rights apply by project, role and environment.

  • Technical access

    Technical accounts and a single entry point carry data access. A user workstation, whatever the role, does not reach a database.

  • Secrets

    Credentials are encrypted and injected at runtime. No secret in clear in code, an image or a log.

Layer-by-layer reference

Twelve layers, four control zones. Each layer states a public mechanism, without exposing implementation detail.

01

Client perimeter

  1. Deployment and hosting

    The platform deploys on your infrastructure, in managed cloud or hybrid mode. Residency is documented in the contract. The architecture does not require an internet egress.

    Residency

  2. Network and isolation

    Only the interface is published. Application services, execution, databases and storage stay on a private network.

    Isolation

02

Access control

  1. Identity and entitlements

    Identity federation to your directory, using market standards. Rights cross project, role and environment.

    Identity

  2. Data and secrets

    Access goes through a single entry point and technical accounts. Secrets are delegated to a vault suited to the environment.

    Secrets

  3. Connectors

    The AI engine is a configuration variable, not an architecture dependency. Each connector is limited to a process and an environment.

    Least privilege

03

Governed execution

  1. Foundation libraries

    Prompt-injection detection is carried by the foundation on governed flows. Document extraction does not call a model by default.

    Foundation

  2. Release to production

    Blocking checks prevent publishing or running a process when the technical contract is incomplete or inconsistent.

    Fail-closed

  3. Runtime

    Each process runs in isolation. Operations logs and model-interaction traces are separated at write time.

    Isolation

  4. Business interfaces

    Some interfaces, including Console, rely on declared queries and rendering, with no model call at runtime.

    Surface

04

Evidence and steering

  1. Evidence and registers

    Each run produces a technical trace and an exportable audit dossier. Full prompts and answers are not logged by default.

    Evidence

  2. Observability

    Cost, usage and indicators attach to the run. Observability plugs into the supervision you already operate.

    Steering

  3. Reversibility

    Engines can be replaced without rebuilding processes. Evidence, configuration and project data export in standard formats.

    Reversibility

NEXA Forward control architecture, from hosting to execution evidence.

What can be verified today

  • Identity and entitlements

    Sign-in through the enterprise identity provider. Project entitlements (read, write, administer), distinct from traced business validations.

  • Secrets and connectors

    Credentials encrypted at capture, stored in a vault suited to the environment. Connectors bound to an owner and, where relevant, to allowed projects.

  • Configurable AI safeguards

    Prompt-injection checks on governed model flows. Sensitive-data policies configured per process, not sold as a separate product.

  • Blocking checks

    A process whose parameters, data or secrets are incomplete is not published. The barrier is technical.

  • Evidence and observability

    Run trace (sources, model, duration, cost) and an exportable audit dossier. Structured logs, without secrets. Detailed prompt logging remains a client decision.

  • Reversibility

    Export of evidence, configuration and project data. The architecture aims to replace engines without rebuilding governance.

Questions for any vendor

This grid applies to NEXA Forward as well as to its competitors. It serves an architecture file, not a brochure.

  1. Is prompt-injection detection a property of the foundation, or an option per project?
  2. What happens if a process fails its quality check? Is there a way to force the release?
  3. What share of interfaces calls an engine at runtime?
  4. Are documents sent to a model to be read, or only when that is necessary?
  5. Are prompts and answers logged by default? Who decides?
  6. Can an older run be reviewed with its exact prompt and model versions?
  7. Can operations teams supervise the system without accessing business content?
  8. Is the reversibility plan a contract clause, or a property you can verify today?

Compliance posture

SOC 2 Type II and ISO 27001 are a public roadmap, not obtained certifications. The GDPR stance is documented product compliance, not a third-party audit. A dated calendar is better than silence.

  • Roadmap SOC 2 Type II target 2027
  • Roadmap ISO 27001 target 2027

A scoping workshop, not a promise.

Ninety minutes with your network, identity and operations architects: flows, encryption, directory, log retention, entitlement matrix. No commercial commitment. A deliverable for your architecture file.

Ready to industrialize your decisions?

The AI that holds up in audit.