Human review at every step
The loop pauses before the agent acts and after it verifies the result. Either point can route to a person, then the run resumes.
Human review at every step, a full audit trail of every action, PHI redaction before anything is saved, and deployment in your own AWS or Azure environment.
Every run is observable, interruptible, and reviewable by your people.
The loop pauses before the agent acts and after it verifies the result. Either point can route to a person, then the run resumes.
Every run produces a structured event trace: the step, the action, the outcome, and any retry reasoning.
Operators see what the agent is doing and what needs approval, right in the browser.
Redaction happens before persistence, and inference can stay inside your boundary.
Sensitive data — including Protected Health Information (PHI) — is redacted with Microsoft Presidio before anything is saved.
Page snapshots are persisted only after redaction — raw, unredacted page state is never stored.
Route model calls to a customer-hosted model so PHI stays inside your infrastructure.
Run fully hosted, or deploy ModelNex in your own AWS or Azure environment.
Customer data is never shared across tenants.
Honest status, not badge collecting: what is in place today and what is in progress.
Built for HIPAA-regulated work: PHI is redacted before anything is stored, access is role-scoped, and every action lands in the audit trail.
SOC 2 Type II certification is in progress. Ask us for the current status and audit timeline.
HITRUST certification is planned to follow SOC 2 Type II.
A security overview document is available on request.
Data is encrypted in transit with TLS and at rest with AES-256.
We never use customer data to train models. Model calls can be routed to endpoints you host, so data stays inside your boundary.
Retention periods are agreed per contract. Only redacted data is retained, and customer data is exported or deleted at termination.
Single-tenant deployment keeps the list short. A current subprocessor list is available on request.
Independent penetration testing is scheduled as part of our SOC 2 Type II program.