Security & Trust

Security built for
project finance data

Nepsis handles data rooms, financial models and contracts for energy projects. Here is how we protect them.

Audit and monitoring

Audit in progress

SOC 2 Type II

Our SOC 2 Type II audit is under way, against the AICPA Trust Services Criteria for security, availability and confidentiality.

Continuously monitored by Bastion

Bastion monitors our controls continuously, not only at audit time.

How we protect your data

No AI training, ever

Your data is never used to train or fine-tune AI models. Not by Nepsis, not by our model providers. Zero data retention models are also available: your documents are processed for your request, then gone.

Choose the models that fit your policies

Your IT and legal teams decide which AI may process your documents. Tell us the rules: EU-only processing, an approved list of providers, zero data retention models only. We set up your workspace to match, and every AI request is routed to a model that meets them. You stay within policy.

Know who accessed what, and when

Every access to your workspace is logged and visible to your admins in real time: which user opened which document, and when. Your audit trail, not ours.

Tested every year, assume-breach

Independent security firms penetration-test the full platform once a year. We work from an assume-breach posture: start from the assumption an attacker is already inside, then close every path they could take.

Hosted in the EU

Production and backups run on AWS in Frankfurt, Germany. Data at rest stays in the European Union.

Questions

How does Nepsis define customer data?

Customer data is any data you would regard as your own confidential data. That covers the documents and data you send to Nepsis for storage or processing, and everything created from them as you use Nepsis: extracted data, analyses, generated documents. It sits at our highest classification level, Customer Confidential, and is protected accordingly. Basic business contact details, such as your name and work email, are classified separately.

Where can I get your SOC 2 report?

We're currently going through the audit. Contact us at contact@nepsis.co for more information on where we are.

Do you use my data to train AI?

No. Neither Nepsis nor our model providers. Zero data retention models are also available.

Where is my data stored?

On AWS in Frankfurt, Germany, for both production and backups.

Can I restrict which AI models process my data?

Yes, per workspace. Contact us to configure it.

Security questionnaire or DPA request

Found a vulnerability? Same address. We answer within 2 business days.

contact@nepsis.co