Security & data · Nodx
Enterprise · Security & data

Security your IT team can sign off

Nodx is built for organizations where data doesn't move without permission: identity you control, data that stays where you decide, and every agent action on the record.

  • SSO
  • MFA
  • Private cloud
  • On premises
  • Your region
  • Approved models
  • Audit log

The controls

What your security review will ask for, in one place.

  • Identity and access

    People sign in the way your organization already does.

    • Single sign-on (SAML, OpenID Connect)
    • Multi-factor authentication
    • SCIM user provisioning
    • Role-based access control
    • Session and device policies
  • Data protection

    Encrypted everywhere, kept only as long as you want.

    • Encryption in transit (TLS 1.2+)
    • Encryption at rest (AES-256)
    • Data residency by region
    • Retention periods you set
    • Deletion on request
  • Governance

    Everything that happens can be seen, and proven.

    • Audit log of every agent action
    • Admin approval for new programs
    • Regular third-party penetration tests
    • Security documentation for procurement
    • A named security contact

Your data stays yours

Three promises behind every deployment.

  • Never used to train models

    What your people write, say and do stays yours. It never trains anyone's models.

  • Processed where you decide

    Pick the region, and every AI call is processed there, and nowhere else.

  • Deleted when you say

    Set the retention you need, and delete any person's data on request.

On the record

Every agent action, logged

Agents work around the clock, so everything they do is written down: what they did, for whom, and why. Admins can review it, and export it for audits.

  • Who, what and when, for every action
  • Searchable by person, agent and program
  • Exportable for internal and external audits
Nodx · Audit log
  • 23:04Plan updated for 214 people in Client roles
  • 23:02Lesson rebuilt: shorter version held better
  • 16:40Mission set: Thursday client meeting
  • 14:12Roleplay completed, evidence recorded
  • 09:30Check-in prepared for a manager

Compliance

The standards and laws your legal team will ask about.

  • SOC 2 infrastructure
  • GDPR
  • UAE data protection law
  • Saudi data protection law
  • ISO 27001-aligned controls
  • Data processing agreement
  • Security questionnaire on request