Security & Controls

Agents your compliance team can say yes to.

Human review at every step, a full audit trail of every action, PHI redaction before anything is saved, and deployment in your own AWS or Azure environment.

Controls

Supervision is built into the run loop.

Every run is observable, interruptible, and reviewable by your people.

Human review at every step

The loop pauses before the agent acts and after it verifies the result. Either point can route to a person, then the run resumes.

Audit trail of every action

Every run produces a structured event trace: the step, the action, the outcome, and any retry reasoning.

Visible supervision surface

Operators see what the agent is doing and what needs approval, right in the browser.

Data handling

Sensitive data is handled as a first-class constraint.

Redaction happens before persistence, and inference can stay inside your boundary.

Sensitive data redacted first

Sensitive data — including Protected Health Information (PHI) — is redacted with Microsoft Presidio before anything is saved.

No unredacted page state stored

Page snapshots are persisted only after redaction — raw, unredacted page state is never stored.

Configurable inference boundary

Route model calls to a customer-hosted model so PHI stays inside your infrastructure.

Your cloud or ours

Run fully hosted, or deploy ModelNex in your own AWS or Azure environment.

Per-tenant isolation

Customer data is never shared across tenants.

Compliance

Built for HIPAA-regulated work.

Honest status, not badge collecting: what is in place today and what is in progress.

HIPAA

Built for HIPAA-regulated work: PHI is redacted before anything is stored, access is role-scoped, and every action lands in the audit trail.

SOC 2 Type II

SOC 2 Type II certification is in progress. Ask us for the current status and audit timeline.

HITRUST CSF

HITRUST certification is planned to follow SOC 2 Type II.

Security practices

The controls your security review will ask about.

A security overview document is available on request.

Encryption in transit and at rest

Data is encrypted in transit with TLS and at rest with AES-256.

No training on customer data

We never use customer data to train models. Model calls can be routed to endpoints you host, so data stays inside your boundary.

Data retention

Retention periods are agreed per contract. Only redacted data is retained, and customer data is exported or deleted at termination.

Subprocessors

Single-tenant deployment keeps the list short. A current subprocessor list is available on request.

Penetration testing

Independent penetration testing is scheduled as part of our SOC 2 Type II program.