Trust Centre

The enterprise foundation of an Intelligent Organisation.

Security, governance, responsible AI, observability and compliance — engineered as first-class product surfaces, not policy documents. Everything a CISO, CIO and Chief Risk Officer needs to say yes.

01 · Security

Enterprise security by default.

NESTSIGNAL is built on a zero-trust architecture with tenant isolation, encryption at every layer and identity as the perimeter — the same posture your CISO already expects from a modern cloud platform.

Identity

SSO via SAML and OIDC. SCIM for provisioning. Enterprise IdP as the source of truth for every session.

Authentication

MFA enforced. Short-lived tokens, rotating refresh, device-bound sessions. Passkeys on the roadmap.

Encryption

TLS 1.3 in transit. AES-256 at rest. Per-tenant key namespaces with support for customer-managed keys on Enterprise.

Workspace isolation

Every organisation is a logically isolated workspace — separate data, separate models, separate audit stream. No cross-tenant reasoning.

Data ownership

Your data is your data. We do not train foundation models on customer content. You retain full ownership and full portability.

02 · Governance

Human control at every decision.

NESTSIGNAL is designed around Human Intelligence™ — every recommendation, mission and outcome has a clear owner, a clear rationale and a clear approval trail. Nothing consequential happens without a person in the loop.

Permissions

Role-based access, attribute-based policies, per-workspace scopes. Least-privilege by default; every grant is auditable.

Approval workflows

Configurable approval chains for missions, spend and external actions. Enforced at the platform level — not the app layer.

Human-in-the-loop

AI Specialists recommend; people approve. High-stakes actions always require a signed-off Decision Page™.

Decision audit

Every decision is a first-class object — inputs, evidence, rationale, approver, outcome. Immutable, exportable, replayable.

Mission approvals

Missions carry their scope, cost envelope and success criteria into approval. Nothing runs without an owner and a boundary.

03 · Responsible AI

Explainable, evidenced and accountable.

We treat AI as a serious professional discipline, not a black box. Every output the platform produces is traceable to its evidence, scored for confidence and grounded in your organisation's connected knowledge.

Human Intelligence™

Recommendations are written to be actioned by a person — what to do, why, what it costs, what it earns, what to watch.

Explainability

Every recommendation exposes its drivers, its data sources, its assumptions and the alternatives that were considered.

Confidence

Forecasts carry confidence bands and sensitivity. Low-confidence outputs are flagged; the platform never bluffs certainty.

Evidence

Every claim links back to the signal, dataset or system-of-record that supports it. Auditable end to end.

Organisation Memory™

Decisions, missions and outcomes are stored as structured memory — the organisation gets smarter after every decision without ever leaking to third parties.

04 · Platform Operations

Know the intelligence platform is operating correctly.

Operational transparency isn't a status page — it's a first-class product surface. You can see, in real time, how healthy the platform is, how Specialists are performing and where execution is drifting.

Platform Health

Live status for every subsystem — connectors, inference, knowledge graph, execution runtime, memory writes.

Live Commissioning

New Specialists, workforces and connectors are commissioned into a workspace with health checks, guardrails and rollback.

Observability

Traces, metrics and logs for every reasoning step. Answers 'why did the platform do that?' in seconds, not days.

Execution monitoring

Every mission is monitored against its plan and its cost envelope. Drift is surfaced early and routed to a human owner.

Specialist health

Per-Specialist quality, latency, cost and grounding scores — so you know your AI workforce is operating correctly.

05 · Compliance

Built for the standards your buyer expects.

NESTSIGNAL is engineered to the controls of the frameworks enterprise procurement teams already trust. Certifications are on a public roadmap — nothing here is aspirational marketing.

SOC 2 Type II

In progress. Controls implemented and observability instrumented. Audit engagement scheduled; report available under NDA to qualified buyers.

GDPR

Full GDPR alignment — lawful basis, DPA, DSR workflows, sub-processor register and appointed DPO channel.

ISO 27001

On the certification roadmap alongside SOC 2. ISMS scoped; policies and control mapping in place today.

Data residency

Regional processing options for the UK, EU and North America. Enterprise workspaces can pin storage and inference to a chosen region.

Privacy

Privacy-by-design. Minimal PII in reasoning paths, configurable retention, right-to-be-forgotten honoured across memory and audit.

06 · Enterprise Architecture

One coherent architecture, seven intelligent layers.

Not a stack of tools. A single operating environment that turns connected data into recommended decisions, coordinated missions and continuous learning — with human accountability at every layer.

  1. 01
    Connected Data

    Every source-of-record connected. Signals captured the moment they happen.

  2. 02
    Business Intelligence

    Signals resolved into business meaning — segments, journeys, accounts, products.

  3. 03
    Connected Business Knowledge

    A living knowledge graph that links data, decisions and outcomes across the organisation.

  4. 04
    Human Intelligence™

    Recommendations a person can act on — with evidence, confidence and rationale attached.

  5. 05
    AI Specialists

    A coordinated workforce that plans, drafts and executes under human approval.

  6. 06
    Execution

    Missions run across the tools your teams already use — with real-time monitoring and rollback.

  7. 07
    Learning

    Every outcome enters Organisation Memory™ — the next decision starts smarter than this one.

For your procurement team

Everything you need in a single Trust Pack.

A single package for security, privacy and vendor risk reviews — kept current and versioned.

Security whitepaper
Sub-processor register
Data Processing Addendum (DPA)
GDPR alignment statement
SOC 2 Type II status letter
ISO 27001 roadmap
Responsible AI policy
Business continuity & DR plan
Vendor security questionnaire response

Ready for a formal review?

We'll share the Trust Pack under NDA and set up a working session with your security and procurement leads.