Enterprise Security Architecture
Nesthing designs controlled workflow boundaries around access, model routing, human approval, evidence, and traceability. Exact controls depend on the selected deployment and must be verified before use.
The deployment data-flow schedule identifies what information is processed, where it is sent, and which provider settings and contractual terms apply. Do not submit data outside the agreed scope.
Encryption in transit and at rest follows the selected hosting and provider configuration. Exact protocols and versions are recorded in deployment evidence when verified.
Hosting region, provider certifications, subprocessors, and retention settings are disclosed for the selected deployment. Provider certifications do not certify Nesthing itself.
Roles, service credentials, retention periods, deletion jobs, and audit events are configured and tested against the agreed scope. Controls not supported by current evidence remain unavailable for public claims.
Retrieved context is sent only to the model endpoint selected for the deployment. Source eligibility, citation checks, release gates, and human review requirements must be acceptance-tested.
Multi-Tenant Isolation Architecture
A proposed deployment may combine tenant-scoped database policies, least-privilege service credentials, idempotency, replay protection, approval gates, and audit events. Each control remains subject to database, runtime, and acceptance evidence before it can be described as operational.