Nera Systems

Trust Center

Our approach to security starts with a different question than most vendors answer. Instead of asking “who is allowed to see this data,” we ask “does anyone need to see it at all.” For most of what Nera does, the answer is no, not even us.

This page covers what our security and privacy posture actually looks like today: what’s certified, what’s architectural, and what’s still in progress. We’d rather tell you exactly where we stand than round up.

Certifications & Compliance

GDPR
Compliant

Nera is GDPR compliant. We act as a data processor under GDPR, and a Data Privacy Addendum (DPA), incorporating the Standard Contractual Clauses for transfers out of the EEA, UK, and Switzerland, is available to all customers.

HIPAA
Compliant

Nera is HIPAA compliant. We sign a Business Associate Agreement (BAA) with covered entities and business associates, and we maintain the administrative, technical, and physical safeguards required of us as a business associate under the HIPAA Security Rule.

SOC 2 Type II
In Progress

We’re actively working with a compliance automation partner to begin our SOC 2 examination. In the interim, the cloud infrastructure Nera runs on (Google Cloud Platform, Microsoft Azure) holds SOC 2 Type II and ISO 27001 certification at the infrastructure layer.

Working With Regulated Data

What’s in scope, what isn’t, and what we need from you before regulated data reaches Nera.

Covered under a signed agreement

The Nera ChatApp, the Excel add-in, and API/SDK access are covered by our BAA and DPA. A signed BAA must be in place before any protected health information is submitted to Nera, and a DPA before personal data subject to GDPR is submitted. We provide our standard BAA and DPA; email info@nera.systems to start.

Not covered

Support channels, email correspondence, and any trial or sandbox environment are not covered, so please don’t send regulated data through them. Third-party tools you connect to Nera are governed by your agreement with that provider, not by ours, and you’re responsible for evaluating them.

Your side of the arrangement. Enforce SSO and multi-factor authentication for your users, keep your encryption keys under your own control, remove access promptly when people leave, and confirm that your intended use is permitted under the regulations that apply to you. Nera’s output is advisory and reviewed by a person; it should not be the system of record for regulated data, and it should not be used for automated decisions about individuals.

The Architecture Behind the Claims

Most security pages describe controls: who can access what, how access is logged, how breaches are handled. Those controls matter, and we have them. But they’re not the reason Nera is different.

The reason is architectural: customer data is encrypted before it ever leaves your environment, using keys you hold. The AI model receives your question and the structure of your data, never the underlying values. Computation happens on encrypted data. Results come back encrypted and are decrypted with your key.

Neither the model provider (Anthropic, Google) nor Nera itself ever has access to your data in a readable form, at any point in the process. That’s not a policy we’ve committed to. It’s a property of how the system works.

The practical consequence: if Nera’s infrastructure were compromised, there’s nothing in it for an attacker to read. Your data was never there in a form anyone could use.

How it actually works
Your data is encrypted before it leaves your environment. It stays that way, even during analysis.
Your dataEncrypted, your keys
The AI modelQuery + structure only
Your answerDecrypted with your key

What This Means Day to Day

Encryption

Your data is encrypted client-side, in your environment, before it’s transmitted. AES-256 at rest, TLS 1.2+ in transit.

No training on your data

Your data is never used to train or improve any model, Nera’s or a third party’s. This is both a contractual commitment and an architectural fact, since we can’t train on data we can’t read.

Model choice, your control

Nera works with Claude and Gemini today, with support for switching models mid-conversation. You can also supply your own model API keys.

Data residency

All production data is currently hosted in United States regions, with no replication elsewhere by default.

Access control

Multi-factor authentication is enforced across all infrastructure. Production access is role-based and limited to named engineering staff.

Track record

Nera has experienced no information security breach and no non-minor security incident since founding in November 2023.

Where We’re Early, and Where We’re Not

Nera is a young company, and we think the honest version of that fact serves you better than a page full of green checkmarks.

What’s mature

The core architectural guarantee, encryption, and the fact that customer data is never readable by Nera or by the model provider. This isn’t a roadmap item. It’s how the system has worked since day one.

What’s in progress

Formal third-party attestation (SOC 2 Type II), independent penetration testing, and a fully documented business continuity and disaster recovery program. These are standard expectations for enterprise procurement, and we’re building toward them on a committed timeline rather than claiming them early.

We’d rather have this conversation directly with your security team than leave it to a badge to answer. If you’re evaluating Nera for a regulated use case, we’re glad to walk through our data flow design, our compliance roadmap and timeline, and answer your team’s specific questions.

Subprocessors

Nera uses a deliberately small set of subprocessors:

Subprocessor Purpose Data Involved
Google Cloud Platform Cloud infrastructure, hosting Encrypted customer content, operational metadata
Microsoft Azure Cloud infrastructure (secondary), hosting Encrypted customer content, operational metadata
Anthropic (Claude) AI model provider Query and dataset schema only, never underlying values
Google (Gemini) AI model provider Query and dataset schema only, never underlying values
Stripe Payment processing Billing and transaction data

We’ll notify customers before adding a new subprocessor with access to their data. Full details are in our DPA.

Infrastructure

Nera runs on Google Cloud Platform (primary) and Microsoft Azure (secondary), both of which maintain SOC 2 Type II and ISO 27001 certification at the infrastructure layer under their own published data processing addenda:

Google Cloud Data Processing Addendum
Microsoft Products and Services Data Protection Addendum

All production data is hosted in United States regions, with no replication elsewhere by default. Nera has no owned data centers or physical infrastructure; physical security is inherited from these providers’ published certifications.

Documents

The policies and agreements that govern how Nera handles your data, and the answers your security team will want first.

Questions?

Reach out to your Nera contact, or email us directly to get your security team connected with ours. We’re glad to walk through the architecture, the compliance roadmap, and your team’s specific questions.

Contact us

This page is provided for informational purposes only and does not constitute legal or compliance advice. Please consult your own advisors about your obligations.
Last updated: August 2026