Security & Governance

Built to deploy where your data must stay.

Sovereign, regulated, or fully air-gapped - with every answer auditable down to the engine, the inputs, and the assumptions that produced it.

Deployment models

Your cloud, your country, or no cloud at all.

Managed cloud

Deployment is cloud-agnostic - your preferred provider and region, sovereign delivery through Moro Hub in the UAE, or fully offline and air-gapped inside your walls - agreed in the Order. Hosted on AWS by default.

The model layer is your choice as well. Nexus is model-agnostic by architecture - a frontier model in the cloud or an approved local model inside your walls - and because the language layer never calculates, the figures and their receipts are identical either way.

In sovereign and regulated markets, these are not preferences - they are procurement gates. Nexus passes them by design.

Access is role-based by design - what a user can ask, see, and export is scoped to their role, and the audit trail records who saw what.

Sovereign cloud

In-jurisdiction delivery where the data may not leave - including ISO 27001-certified, PDPL-aligned sovereign cloud infrastructure in the UAE as one worked example of a jurisdiction-agnostic pattern.

Air-gapped

Fully disconnected deployment for the environments that require it. The whole trust stack - receipts, refusal, audit export - travels with it.

Data protection

Commitments, not adjectives.

Encryption

TLS 1.2 or higher in transit; industry-standard encryption at rest. (DPA, Schedule C.)

Access control

Role-based access on least privilege, multi-factor authentication for systems handling personal data, periodic access reviews and revocation. (DPA, Schedule C.)

No training on your data

Client data is never used to train or fine-tune models made available to third parties without prior written consent - contractually, not as policy. (Platform Terms §6.2; DPA §3.3.)

Data residency & subprocessors

Processing region is set in the Order - jurisdiction-specific and sovereign delivery available; the contractual default is the United States. Subprocessors are listed, flowed-down, and change-notified with an objection right. (Platform Terms §6.3; DPA §6.)

Incident notification

Confirmed security incidents notified without undue delay - and in any event within seventy-two hours - with the information you need for your own obligations. (Platform Terms §6.5; DPA §5.2.)

Audit rights

Annual client audit via independent auditor, satisfiable by recognized third-party reports and written security summaries. (DPA §5.3.)

Architecture as a control

Hallucination is a governance risk. The architecture removes the main vector.

In a generative system, the model that talks is the model that answers - and it cannot tell you when it is wrong. In Nexus, the AI that talks never does the math:

No minted numbers

The language model routes and narrates; named, versioned engines compute every figure. No figure returns without a bound engine result behind it.

Refusal by design

Unverifiable inputs are refused, with the reason - and the refusal is logged like any other result.

Reproducibility

Same inputs and engine version, identical figures - so any answer can be re-run and checked months later, in front of an auditor.

Audit export

Every session exports engines, inputs, assumptions, and figures - a package your own statisticians can check, line by line.

Versioned engines

Nothing changes silently: every answer records which engine version ran. Draft engines are born quarantined and promoted by a person.

Access & lineage

Who asked what, answered from which data, when - role-based to the engine and dataset level, with source and vintage on every input.

Infrastructure & assurance

Certifications, attributed honestly.

Nexus runs on infrastructure certified to ISO 27001, SOC 1, SOC 2, and SOC 3 (AWS), with equivalently certified sovereign options. Rebirth's own technical and organizational controls - encryption, access control, network security, incident response, vendor management, personnel, and vulnerability management - are documented contractually in the DPA's security schedule and open to client audit. The commitments live in the contract, not the brochure.

The paper trail

Send this page to procurement.

CONTINUE THE STORY Next: Your interface, our engineWhite-label grounded intelligence for GIS partners. Or skip aheadBring your hardest question.