Security
Built into your estate. Control stays yours.
NEXA Forward does not sit beside the information system. It integrates by keeping identity, entitlements, technical access and secrets strictly apart.
This page states control principles and mechanisms. Technologies, settings and client environments are covered in a scoping workshop, under a confidentiality agreement.
Policy enforced
- Identity
- Entitlements
- Technical access
- Secrets
Four separations, one policy
No user, process or agent reaches a data source directly. Everything goes through a single entry point that enforces policy.
-
Identity
Authentication is delegated to your enterprise directory. The platform stores no user passwords.
-
Entitlements
Once identity is validated, rights apply by project, role and environment.
-
Technical access
Technical accounts and a single entry point carry data access. A user workstation, whatever the role, does not reach a database.
-
Secrets
Credentials are encrypted and injected at runtime. No secret in clear in code, an image or a log.
Layer-by-layer reference
Twelve layers, four control zones. Each layer states a public mechanism, without exposing implementation detail.
01
Client perimeter
-
Deployment and hosting
The platform deploys on your infrastructure, in managed cloud or hybrid mode. Residency is documented in the contract. The architecture does not require an internet egress.
Residency
-
Network and isolation
Only the interface is published. Application services, execution, databases and storage stay on a private network.
Isolation
02
Access control
-
Identity and entitlements
Identity federation to your directory, using market standards. Rights cross project, role and environment.
Identity
-
Data and secrets
Access goes through a single entry point and technical accounts. Secrets are delegated to a vault suited to the environment.
Secrets
-
Connectors
The AI engine is a configuration variable, not an architecture dependency. Each connector is limited to a process and an environment.
Least privilege
03
Governed execution
-
Foundation libraries
Prompt-injection detection is carried by the foundation on governed flows. Document extraction does not call a model by default.
Foundation
-
Release to production
Blocking checks prevent publishing or running a process when the technical contract is incomplete or inconsistent.
Fail-closed
-
Runtime
Each process runs in isolation. Operations logs and model-interaction traces are separated at write time.
Isolation
-
Business interfaces
Some interfaces, including Console, rely on declared queries and rendering, with no model call at runtime.
Surface
04
Evidence and steering
-
Evidence and registers
Each run produces a technical trace and an exportable audit dossier. Full prompts and answers are not logged by default.
Evidence
-
Observability
Cost, usage and indicators attach to the run. Observability plugs into the supervision you already operate.
Steering
-
Reversibility
Engines can be replaced without rebuilding processes. Evidence, configuration and project data export in standard formats.
Reversibility
What can be verified today
-
Identity and entitlements
Sign-in through the enterprise identity provider. Project entitlements (read, write, administer), distinct from traced business validations.
-
Secrets and connectors
Credentials encrypted at capture, stored in a vault suited to the environment. Connectors bound to an owner and, where relevant, to allowed projects.
-
Configurable AI safeguards
Prompt-injection checks on governed model flows. Sensitive-data policies configured per process, not sold as a separate product.
-
Blocking checks
A process whose parameters, data or secrets are incomplete is not published. The barrier is technical.
-
Evidence and observability
Run trace (sources, model, duration, cost) and an exportable audit dossier. Structured logs, without secrets. Detailed prompt logging remains a client decision.
-
Reversibility
Export of evidence, configuration and project data. The architecture aims to replace engines without rebuilding governance.
Questions for any vendor
This grid applies to NEXA Forward as well as to its competitors. It serves an architecture file, not a brochure.
- Is prompt-injection detection a property of the foundation, or an option per project?
- What happens if a process fails its quality check? Is there a way to force the release?
- What share of interfaces calls an engine at runtime?
- Are documents sent to a model to be read, or only when that is necessary?
- Are prompts and answers logged by default? Who decides?
- Can an older run be reviewed with its exact prompt and model versions?
- Can operations teams supervise the system without accessing business content?
- Is the reversibility plan a contract clause, or a property you can verify today?
Compliance posture
SOC 2 Type II and ISO 27001 are a public roadmap, not obtained certifications. The GDPR stance is documented product compliance, not a third-party audit. A dated calendar is better than silence.
- Roadmap SOC 2 Type II target 2027
- Roadmap ISO 27001 target 2027
A scoping workshop, not a promise.
Ninety minutes with your network, identity and operations architects: flows, encryption, directory, log retention, entitlement matrix. No commercial commitment. A deliverable for your architecture file.