Sign In Get Early Access
Security

Your process data stays yours.

Nexwatt agents read and write sensitive operational data by design — CRM records, HR data, financial approvals. Security wasn't retrofitted. The credential vault, field-level redaction, and role-based access controls were in the architecture before the first connector shipped.

Four controls built into the platform.

Encryption at rest and in transit

All data stored in the Nexwatt platform is encrypted at rest using AES-256. All data in transit is encrypted via TLS 1.3. This includes your process definitions, agent configurations, connector credentials, and audit logs. No plaintext data at any storage layer.

Credential vault — secrets never in agent definitions

API keys, OAuth tokens, and connection credentials are stored in a separate secrets vault isolated from the agent runtime. Agent definitions reference credentials by vault path, never by value. A compromised agent definition doesn't expose your credentials.

Role-based access control

Three default roles: Admin (full access), Editor (build and deploy agents), Reviewer (audit log and escalation queue only). Custom roles available on the Custom tier. Access is scoped to workspaces — contractors or reviewers can be added to specific workspaces without seeing the full account.

Full audit log with configurable redaction

Every agent action is logged — timestamp, step, action, outcome, confidence score. Input data in logs is redacted at the field level based on your data policy. You control which fields appear in logs, which are redacted, and which are fully excluded. Export logs to CSV or push to your SIEM via the API.

Honest about where we are on compliance.

We're an early-stage company. Here's what's in place now, what's in design, and what's on the roadmap — without claiming certifications that don't exist yet.

In Design

SOC 2 Type II (in progress)

SOC 2 controls have been designed into the platform architecture. We are not yet SOC 2 certified. We are working toward audit readiness and will publish our Type II report when it is complete. We will not claim certification before it exists.

Available Now

GDPR-ready data handling

Data residency in the US. Data Processing Addendum (DPA) available on request. Right-to-erasure workflow available via API. Personal data in agent inputs is scoped to run context and not retained beyond your configured log retention period.

Early Access Scope

US-based customers only

During early access, Nexwatt is available to US-based companies only. Data is stored and processed in US regions. International availability will be announced with appropriate compliance documentation in place for each region.

By Design

No training on your data

Your process documentation, agent definitions, and the data your agents process are not used to train shared models. Confidence calibration data is scoped to your account and not shared across customers. You can request deletion of all account data at any time.

Responsible disclosure.

If you discover a security vulnerability in the Nexwatt platform, please contact us at [email protected]. We ask that you give us reasonable time to address the issue before public disclosure. We will acknowledge your report within 2 business days and keep you informed of our progress.

Disclosure guidelines
  • Do not access or modify data that is not yours
  • Do not perform denial-of-service attacks
  • Provide enough detail to reproduce the issue
  • Allow 30 days for remediation before public disclosure