Enterprise Security
& Compliance Controls
OmniNuera enforces multi-layered zero-trust guardrails to safeguard corporate vector tokens, maintain strict regulatory compliance, and guarantee sovereign tenant database isolation.
Regulatory Defense Frameworks
HIPAA & Health Data Protection
Real-time vector parser autodetects patient names, medical codes, prescription numbers, and clinical diagnostic recordsโmasking sensitive PHI prior to AI inference.
SOC 2 Type II Security Controls
Independent database schemas, automated AES-256 key rotation, role-based access controls (RBAC), and immutable cryptographic logs keep your enterprise audit-ready.
PCI-DSS Payment Guardrails
Prevent payment account data leaks. Inline regex algorithms detect 16-digit primary account numbers (PANs), CVVs, and banking routing codes before prompt dispatch.
GDPR & Data Isolation
Each organization runs in an isolated SQL Server database with AES-256 encryption. Dedicated EU geo residency nodes are on the roadmap; today residency is controlled by where you host the platform.
ISO / IEC 27001 Encryption
Provider API keys and sensitive credentials are encrypted using AES-256-GCM at rest. Traffic uses TLS in transit.
Air-Gapped / On-Prem Mode
Route confidential workloads to self-hosted Ollama so sensitive prompts never leave your network. Packaged Helm/air-gap installers are on the roadmap.
Sovereign Multi-Region Infrastructure Nodes
Select a geographic zone below to inspect active database residency rules, vector containment regions, and encryption specifications.
North America East Node (us-east-1)
Primary North American control plane. Compliant with HIPAA, SOC 2 Type II, and US Federal data residency regulations.
Security Control & Audit Matrix
| Compliance Standard | Mandatory Requirement | OmniNuera Control Mechanism | Audit Status |
|---|---|---|---|
| HIPAA / PHIPA | Sanitize patient data prior to egress | Real-time DLP patterns for medical/PII entities before LLM egress | ๐งญ Pattern ready |
| SOC 2 Type II | Tenant database isolation & access logs | Dedicated SQL DBs + time-bound operator tickets + audit events | ๐งญ Controls ready |
| PCI-DSS Level 1 | Prevent PAN / cardholder data leakage | Luhn-aware regex redacts primary account numbers in prompts | ๐งญ Pattern ready |
| GDPR / EU Law | Right-to-be-forgotten & data isolation | Per-tenant SQL isolation + purge path (dedicated EU geo nodes roadmap) | ๐งญ Partial |
| FedRAMP / Air-Gap | Minimize external cloud dependencies | Local Ollama routing when self-hosted (Helm/air-gap pack roadmap) | ๐งญ Partial |
Need Custom Security BAA or SOC 2 Reports?
Our security engineering team can provide enterprise BAA agreements, SOC 2 compliance packets, and custom deployment architecture reviews.
