1. Home
  2. Security

Trust

Security

What we do to protect customer data and workloads, stated plainly — including what is in place today and what is still being built.

Our certification position, stated up front: NXAARA does not currently hold ISO 27001, SOC 2 or any equivalent third-party certification. A formal certification programme is underway and we will publish the certificates when they are issued and not before. If your procurement process requires a certificate today, we would rather you know that now than at the end of a review cycle. We can supply a completed security questionnaire, architecture documentation and evidence of the controls below in the meantime.

Data residency

Customer data — datasets, volumes, model artefacts, document corpora and logs — is stored and processed in the United Arab Emirates, in Dubai, on infrastructure operated by EADPAG. Data does not leave the region unless you deliberately move it. Where residency is a contractual or regulatory requirement for you, we will state it in the agreement rather than only on a web page.

Tenant isolation

Each customer organisation is a separate tenant with its own projects, storage and network boundary. A GPU attached to your instance is exclusively yours for the life of that instance and is wiped before reallocation. Object storage is namespaced per project with access mediated by project-scoped credentials. For workloads where shared infrastructure is unacceptable in principle, Private AI provides dedicated single-tenant, on-premises and air-gapped deployment.

Encryption

Data in transit is protected with TLS 1.2 or higher on all external endpoints, including the console, the API and object storage. Data at rest is encrypted on block and object storage. Secrets, API keys and registry credentials are held in an encrypted store and are never written to logs.

Access control

Access is organised around projects. Members hold roles within a project, and roles determine what they can provision, read, modify, promote and spend. API keys are scoped to a project and optionally to specific services, and can carry their own rate limits. Keys can be rotated or revoked individually without disturbing anything else. Internal administrative access to production systems is limited to named engineers, requires multi-factor authentication, and is logged.

Customer data and model training

We do not train models on customer data. Datasets uploaded to a project are used for that customer's own jobs and for nothing else. We do not pool customer data across accounts, we do not sample it for internal quality work, and we do not use it to improve base models. Inference request logging is disabled by default; where you enable it, logs are project-scoped with a retention period you set and can delete.

Audit logging

Provisioning actions, dataset registrations, tuning jobs, evaluations, model promotions, key creation and permission changes are recorded with actor, timestamp and — for promotions — the evaluation the decision was based on. Audit records are exportable in machine-readable form. This exists because in a regulated review the question is never whether you were careful; it is whether you can show it.

Vulnerability handling

If you believe you have found a security vulnerability, email security@nxaara.com with enough detail to reproduce it. We will acknowledge receipt, keep you informed while we investigate, and credit you if you would like to be credited. Please do not test against other customers' data or run denial-of-service testing against shared infrastructure. We will not pursue legal action against researchers who act in good faith within those limits.

Business continuity

Persistent volumes and object storage are replicated within the region. Customers are responsible for their own backup policy for anything they consider irreplaceable, and we recommend checkpointing long training runs to persistent storage rather than local disk. Recovery objectives for dedicated and private deployments are agreed contractually and sized to the workload rather than assumed from a general policy.

Subprocessors

We maintain a list of subprocessors with access to customer data and will provide it on request, along with advance notice of material changes for customers under contract.

Asking us harder questions

Security questionnaires, architecture reviews and evidence requests are welcome and are handled by engineers rather than by a sales team reading from a template. Write to security@nxaara.com or use the contact form.

Last reviewed 31 July 2026.