Security & Controls

Agents your compliance team can say yes to.

Human review at every step, an append-only audit trail of every action, encryption with your own key, and tenant isolation enforced at the database layer, with single-tenant deployment in your own AWS or Azure environment available.

SOC 2 Type II & HIPAA in progress Trust Center →
Controls

Supervision is built into the run loop.

Every run is observable, interruptible, and reviewable by your people.

Human review at every step

The loop pauses before the agent acts and after it verifies the result. Either point can route to a person, then the run resumes.

Audit trail of every action

Every run produces a structured event trace: the step, the action, the outcome, and any retry reasoning.

Visible supervision surface

Operators see what the agent is doing and what needs approval, right in the browser.

Data handling

Where case data lives, and who can reach it.

The deployment boundary is yours to choose, and so is the model endpoint the agent talks to.

Encryption is mandatory, not a setting

Sensitive fields are encrypted at rest with a key you supply. Without that key, the deployment refuses to start.

You choose the inference boundary

The agent sends page context to whichever model endpoint you configure. Point it at a model you host and that context never leaves your infrastructure.

Your cloud or ours

Multi-tenant by default in our cloud. Deploy ModelNex single-tenant in your own AWS or Azure environment when your security review calls for it.

Append-only audit trail

Every action is written to an audit log that cannot be edited or deleted in place, retained for seven years by default.

Per-tenant isolation

Customer data is never shared across tenants; isolation is enforced at the database layer.

Compliance

Live compliance status, not a badge on a page.

Honest status, not badge collecting: our SOC 2 Type II and HIPAA programs are in progress and monitored continuously with Vanta, and the Trust Center shows where each one stands.

Trust Center

Where each program stands, the controls in place today, and the evidence behind them, updated as it changes rather than once a year.

Open the Trust Center

SOC 2 Type II: in progress

Our SOC 2 Type II program is in progress and monitored continuously. Control-by-control status is live in the Trust Center.

HIPAA: in progress

Our HIPAA program is in progress. In place today: sensitive data encrypted at rest with your key, role-scoped access, and every action in the append-only audit trail.

Security practices

The controls your security review will ask about.

A security overview document is available on request.

Encryption in transit and at rest

Data is encrypted in transit with TLS and at rest with AES-256.

No training on customer data

We never use customer data to train models. Model calls can be routed to endpoints you host, so data stays inside your boundary.

Data retention

Retention periods are agreed per contract, and customer data is exported or deleted at termination.

Subprocessors

We keep the list short. A current subprocessor list is available on request.