Security & Compliance
Engineered for enterprise scale, zero trust, and multi-cloud (Microsoft Azure & AWS) native security. Discover how Nisol AI protects your data, agent workflows, and vector architectures.
Security & Compliance Highlights
Azure & AWS Multi-Cloud Security
Deployed on Microsoft Azure and AWS infrastructure utilizing isolated VNets/VPCs, Azure OpenAI Service, AWS Bedrock, and Azure Key Vault / KMS.
End-to-End Encryption
TLS 1.3 enforced in-transit across all HTTP/API endpoints and AES-256 encryption at-rest for vector databases and object stores.
AI Guardrails & Zero Training
Active prompt injection defenses, automated PII redaction, and strict guarantees that customer data is never used to train public LLMs.
SOC 2 & ISO 27001 Alignment
Architected around SOC 2 Trust Services Criteria, ISO/IEC 27001 controls, and ISO 42001 (Artificial Intelligence Governance).
01.Zero-Trust Security Philosophy
At Nisol AI, security is not an afterthought or a marketing checkbox — it is a core architectural pillar of every agent workflow, RAG pipeline, and cloud deployment we engineer.
We operate under a strict Zero-Trust architecture principle: "Never trust, always verify." Every API request, agent communication boundary, model execution call, and database query must be authenticated, authorized, and logged regardless of whether it originates inside or outside the network perimeter.
02.Microsoft Azure & AWS Cloud Infrastructure (Mumbai, India Region)
Our primary production infrastructure, vector databases, and AI model endpoints are deployed in Mumbai, India (Azure Central India & AWS Asia Pacific ap-south-1), capitalizing on tier-1 MeitY empaneled cloud data centers:
Isolated VNets & VPC Environments
Compute and vector database resources operate within private Azure Virtual Networks (VNets) and AWS VPCs with strict subnet isolation and no direct public internet exposure for data stores.
Azure DDoS & WAF Protection
Azure Front Door WAF and AWS Shield inspect edge web traffic to automatically mitigate OWASP Top 10 vulnerabilities, botnets, and DDoS attacks.
Azure OpenAI & AWS Bedrock Endpoints
Foundational LLM processing takes place via private Azure OpenAI Service and AWS Bedrock endpoints, ensuring enterprise data remains securely contained within dedicated cloud perimeters.
Multi-Region Redundancy
Applications and storage replicas are distributed across multiple Azure Availability Zones and AWS regions to guarantee zero single points of failure.
03.Data Encryption & Key Management
Nisol AI enforces mandatory encryption across data lifecycles—whether data is moving across the network or stored in persistent databases:
Encryption In Transit (TLS 1.3)
Enforced EverywhereAll browser sessions, microservice communications, and external API requests require TLS 1.3 encryption. HTTP traffic is automatically redirected to HTTPS with Strict-Transport-Security (HSTS) headers enabled.
Encryption At Rest (AES-256, Azure Key Vault & AWS KMS)
FIPS 140-2 ValidatedAll relational databases, pgvector stores, blob storage, and system logs are encrypted at rest using AES-256 encryption. Encryption keys are managed and rotated via Azure Key Vault and AWS Key Management Service (KMS).
Tenant Data Isolation (PostgreSQL RLS)
Strict Row-Level SecurityPostgreSQL database architecture uses Row Level Security (RLS) policies ensuring complete data isolation between enterprise accounts. A tenant can never query or view another client's data.
4. AI Guardrails & Prompt Safety Architecture
Deploying LLMs into production requires multi-layered safety guardrails to ensure reliability, prevent hallucinations, and reject malicious prompt injection attempts:
Automated real-time evaluation engines benchmark model response accuracy, latency, and groundness against reference context prior to delivering output.
Input sanitization filters prevent prompt injection, system prompt leakage, jailbreaks, and unauthorized tool execution.
Sensitive personal identifiable information (SSNs, credit card numbers, confidential keys) is automatically masked prior to model processing.
We configure foundational model APIs with zero-data-retention parameters, guaranteeing that enterprise queries are erased immediately after inference.
05.IAM & Role-Based Access Controls
Access to Nisol AI development and production environments is controlled through granular Identity and Access Management (IAM):
- Least-Privilege Authorization & Entra ID (Azure AD): Personnel access is governed via Microsoft Entra ID (Azure AD) SSO, SAML 2.0, and strict Role-Based Access Controls (RBAC).
- Mandatory Multi-Factor Authentication (MFA): Hardware key or TOTP MFA is enforced on all internal developer, Azure portal, cloud console, and database accounts.
- Immutable Audit Logging: All administrative access events and configuration changes are recorded in immutable Azure Monitor / AWS CloudTrail logs.
06.Compliance Standards & Framework Alignment
Nisol AI's security practices align with internationally recognized cybersecurity and governance standards:
DPDP Act 2023 & CERT-In (India)
Compliant with India's Digital Personal Data Protection Act (DPDP 2023) data residency and CERT-In 6-hour incident reporting rules.
SOC 2 Type II Alignment
Controls mapped across Security, Confidentiality, and Availability Trust Services Criteria.
ISO/IEC 27001 & ISO 42001
Adherence to Information Security Management and pioneering Artificial Intelligence Governance standards.
GDPR, CCPA & HIPAA Ready
Infrastructure supporting international privacy rights, BAAs, and isolated enterprise tenant data environments.
07.Vulnerability Management & Auditing
We maintain continuous visibility into potential software vulnerabilities:
- Automated Code Scanning: Static Application Security Testing (SAST) integrated directly into GitHub CI/CD build pipelines.
- Dependency Monitoring: Real-time dependency vulnerability tracking to immediately patch outdated npm or Python packages.
- Penetration Testing: Periodic third-party web application and cloud architecture security audits.
08.Disaster Recovery & Availability
Nisol AI ensures enterprise service continuity through robust backup and recovery targets:
Continuous Point-in-Time Recovery (PITR) for PostgreSQL relational databases.
Automated infrastructure deployment scripts (Terraform/CloudFormation) for rapid region restoration.
09. Incident Response & Responsible Disclosure
We take all security reports seriously. If you suspect a security vulnerability or wish to report an incident regarding Nisol AI infrastructure, please contact our security response team immediately:
Nisol AI Security Operations Center (SOC)
Security Email: contact@nisolai.com
Response SLA: Within 24 hours of notification receipt
