Nera Systems

Trust Center

Our approach to security starts with a different question than most vendors answer. Instead of asking “who is allowed to see this data,” we ask “does anyone need to see it at all.” For most of what Nera does, the answer is no — not even us.

This page covers what our security and privacy posture actually looks like today: what’s certified, what’s architectural, and what’s still in progress. We’d rather tell you exactly where we stand than round up.

Certifications & Compliance

🌐
GDPR
Compliant

Nera acts as a data processor under GDPR. A Data Processing Agreement (DPA) is available to all customers.

HIPAA
Compliant

A Business Associate Agreement (BAA) is available for customers handling protected health information.

SOC 2 Type II
In Progress

We’re actively working with a compliance automation partner to begin our SOC 2 examination. In the interim, the cloud infrastructure Nera runs on (Google Cloud Platform, Microsoft Azure) holds SOC 2 Type II and ISO 27001 certification at the infrastructure layer.

The Architecture Behind the Claims

Most security pages describe controls: who can access what, how access is logged, how breaches are handled. Those controls matter, and we have them. But they’re not the reason Nera is different.

The reason is architectural: customer data is encrypted before it ever leaves your environment, using keys you hold. The AI model receives your question and the structure of your data, never the underlying values. Computation happens on encrypted data. Results come back encrypted and are decrypted with your key.

Neither the model provider (Anthropic, Google) nor Nera itself ever has access to your data in a readable form, at any point in the process. That’s not a policy we’ve committed to. It’s a property of how the system works.

The practical consequence: if Nera’s infrastructure were compromised, there’s nothing in it for an attacker to read. Your data was never there in a form anyone could use.

How it actually works
Your data is encrypted before it leaves your environment. It stays that way, even during analysis.
Your dataEncrypted, your keys
The AI modelQuery + structure only
Your answerDecrypted with your key

What This Means Day to Day

Encryption

Your data is encrypted client-side, in your environment, before it’s transmitted. AES-256 at rest, TLS 1.2+ in transit.

No training on your data

Your data is never used to train or improve any model, Nera’s or a third party’s. This is both a contractual commitment and an architectural fact, since we can’t train on data we can’t read.

Model choice, your control

Nera works with Claude and Gemini today, with support for switching models mid-conversation. You can also supply your own model API keys.

Data residency

All production data is currently hosted in United States regions, with no replication elsewhere by default.

Access control

Multi-factor authentication is enforced across all infrastructure. Production access is role-based and limited to named engineering staff.

Track record

Nera has experienced no information security breach and no non-minor security incident since founding in November 2023.

Where We’re Early, and Where We’re Not

Nera is a young company, and we think the honest version of that fact serves you better than a page full of green checkmarks.

What’s mature

The core architectural guarantee, encryption, and the fact that customer data is never readable by Nera or by the model provider. This isn’t a roadmap item — it’s how the system has worked since day one.

What’s in progress

Formal third-party attestation (SOC 2 Type II), independent penetration testing, and a fully documented business continuity and disaster recovery program. These are standard expectations for enterprise procurement, and we’re building toward them on a committed timeline rather than claiming them early.

We’d rather have this conversation directly with your security team than leave it to a badge to answer. If you’re evaluating Nera for a regulated use case, we’re glad to walk through our data flow design, our compliance roadmap and timeline, and answer your team’s specific questions.

Subprocessors

Nera uses a deliberately small set of subprocessors:

Subprocessor Purpose Data Involved
Google Cloud Platform Cloud infrastructure, hosting Encrypted customer content, operational metadata
Microsoft Azure Cloud infrastructure (secondary), hosting Encrypted customer content, operational metadata
Anthropic (Claude) AI model provider Query and dataset schema only, never underlying values
Google (Gemini) AI model provider Query and dataset schema only, never underlying values
Stripe Payment processing Billing and transaction data

We’ll notify customers before adding a new subprocessor with access to their data. Full details are in our DPA.

Infrastructure

Nera runs on Google Cloud Platform (primary) and Microsoft Azure (secondary), both of which maintain SOC 2 Type II and ISO 27001 certification at the infrastructure layer under their own published data processing addenda:

Google Cloud Data Processing Addendum
Microsoft Products and Services Data Protection Addendum

All production data is hosted in United States regions, with no replication elsewhere by default. Nera has no owned data centers or physical infrastructure; physical security is inherited from these providers’ published certifications.

Documents

The policies and agreements that govern how Nera handles your data, and the answers your security team will want first.

Questions?

Reach out to your Nera contact, or email us directly to get your security team connected with ours. We’re glad to walk through the architecture, the compliance roadmap, and your team’s specific questions.

Contact us

Last updated: August 2026