Your process data stays yours.
Nexwatt agents read and write sensitive operational data by design — CRM records, HR data, financial approvals. Security wasn't retrofitted. The credential vault, field-level redaction, and role-based access controls were in the architecture before the first connector shipped.
Four controls built into the platform.
All data stored in the Nexwatt platform is encrypted at rest using AES-256. All data in transit is encrypted via TLS 1.3. This includes your process definitions, agent configurations, connector credentials, and audit logs. No plaintext data at any storage layer.
API keys, OAuth tokens, and connection credentials are stored in a separate secrets vault isolated from the agent runtime. Agent definitions reference credentials by vault path, never by value. A compromised agent definition doesn't expose your credentials.
Three default roles: Admin (full access), Editor (build and deploy agents), Reviewer (audit log and escalation queue only). Custom roles available on the Custom tier. Access is scoped to workspaces — contractors or reviewers can be added to specific workspaces without seeing the full account.
Every agent action is logged — timestamp, step, action, outcome, confidence score. Input data in logs is redacted at the field level based on your data policy. You control which fields appear in logs, which are redacted, and which are fully excluded. Export logs to CSV or push to your SIEM via the API.
Honest about where we are on compliance.
We're an early-stage company. Here's what's in place now, what's in design, and what's on the roadmap — without claiming certifications that don't exist yet.
SOC 2 Type II (in progress)
SOC 2 controls have been designed into the platform architecture. We are not yet SOC 2 certified. We are working toward audit readiness and will publish our Type II report when it is complete. We will not claim certification before it exists.
GDPR-ready data handling
Data residency in the US. Data Processing Addendum (DPA) available on request. Right-to-erasure workflow available via API. Personal data in agent inputs is scoped to run context and not retained beyond your configured log retention period.
US-based customers only
During early access, Nexwatt is available to US-based companies only. Data is stored and processed in US regions. International availability will be announced with appropriate compliance documentation in place for each region.
No training on your data
Your process documentation, agent definitions, and the data your agents process are not used to train shared models. Confidence calibration data is scoped to your account and not shared across customers. You can request deletion of all account data at any time.
Responsible disclosure.
If you discover a security vulnerability in the Nexwatt platform, please contact us at [email protected]. We ask that you give us reasonable time to address the issue before public disclosure. We will acknowledge your report within 2 business days and keep you informed of our progress.
- Do not access or modify data that is not yours
- Do not perform denial-of-service attacks
- Provide enough detail to reproduce the issue
- Allow 30 days for remediation before public disclosure