Notrix

Security

For the data you cannot afford to leak.

Company Brain reads your most sensitive systems. That only works if the controls around it are boring, provable, and open to your inspection.

Permissions are inherited, not applied

Access rights are captured at ingestion and travel with the content. If a user cannot open a file in the source system, Company Brain will not surface it to them.

Your data does not train models

Inputs, outputs and uploaded documents are never used for training. We require zero-retention terms from every model provider we route to.

Every action is recorded

Each agent run is logged end to end — sources read, decisions taken, systems written to, approvals given. Exportable, and reversible where it matters.

You choose where it runs

Our environment or yours. Regional processing for residency requirements, and full deployment into your own cloud where that is the only acceptable answer.

Standards

Where we actually stand

We publish status plainly rather than implying certifications we do not hold. Each entry says exactly where it is, and this page is updated as audits complete.

SOC 2 Type II

In progress

Controls built against the Trust Services Criteria. Audit underway; documentation and questionnaire responses available under NDA.

GDPR

Compliant

Data processing agreements, disclosed sub-processors, full data subject rights, and EU-region processing where required. A regulation, not a certification.

EU AI Act

Readiness

A regulation rather than a certification. We build for its obligations: documentation, traceability, human oversight and disclosure.

ISO/IEC 27001

Aligned

Security management practices mapped to Annex A controls. Certification is on the roadmap and will be published here when issued.

ISO/IEC 42001

Aligned

AI management system practices covering impact assessment, model lifecycle governance and monitoring of deployed systems.

Data residency

Available

Regional processing, configurable retention and deletion, and deployment into infrastructure you own and operate.

Bring your security team to the first call.

We would rather answer the hard questions up front than find a blocker three months into a deployment. Send your questionnaire to hello@notrix.ai and we will work through it with you under NDA.