Security & deployment

A compliance platform has to clear its own bar

NVector holds the record of what an institution has and has not secured. That makes it a high-value target, and we build it accordingly. Here is what is actually in place — and what is not yet, stated plainly.

Controls in the platform

Field-level encryption

Sensitive columns — integration credentials, contact details, electronic signatures, device identifiers and audit-trail IP addresses — are encrypted with AES-256-GCM using a key held separately from the application secret, so rotating one does not compromise the other.

Role-based access control

Access is granted through roles and assignments scoped to organisational units. Evidence carries sensitivity classifications, and the platform enforces which roles may open which level.

Tenant isolation

Every record is owned by an organisation and reached only through that ownership chain. One customer's data is never reachable from another customer's session.

Short-lived sessions

Authentication uses short-lived signed access tokens with separate refresh credentials and a configurable session lifetime, so a stolen token has a narrow window of use.

Immutable audit trail

Every create, update and delete is recorded with the actor, timestamp and before/after values. Trail entries cannot be modified or removed through the application.

Hardened by default

Parameterised queries throughout, strict origin allow-lists for cross-origin and form submissions, request and upload size limits, and a configuration that refuses to start in an unsafe production state.

Deployment models

Regulators and internal policies differ on where compliance data may live. Pick the shape that fits yours.

Deployment options and what each implies.
ModelWhere it runsAI featuresTypically chosen by
CloudHosted and managed by NVectorAvailableSmall and mid-size institutions
Cloud without AIHosted and managed by NVectorDisabled — nothing leaves for inferenceStrict data-sharing policies
On-premiseYour data centre, your controlsOptional, using your own provider keyData residency requirements
Air-gappedFully isolated, no internet at allLocal model onlyGovernment and critical infrastructure

Data sent to AI features

Where AI assistance is enabled, data is sanitised before it leaves the platform: personally identifiable information — names, national identity numbers, account numbers and phone numbers — is stripped so the model receives anonymised text.

AI output is always advisory. It drafts, scores and suggests; a named human approves before anything is recorded as a compliance decision or sent to a regulator.

If that is still not acceptable under your policy, run the cloud-without-AI, on-premise or air-gapped model and the feature is simply not present.

Being straight about maturity

NVector is an actively developed product. We hold no third-party security certification today and we will not imply otherwise on a marketing page — a compliance vendor claiming unverified attestations would be the wrong place to start a relationship.

What we will do is answer a security questionnaire in full, walk your team through the architecture, and support a penetration test against a dedicated environment before you commit.

Found something? Email security@nvector.io. We will acknowledge within two business days and will not pursue good-faith researchers.

Send us your security questionnaire

We will complete it properly rather than pointing you at a trust page.