Skip to main content

Docs · Trust

Security and compliance

Nebula holds the documents and decisions that define your engagements, so it is built to keep them safe and to satisfy the people who ask the hard questions: your clients, your auditors, and your own risk team.

For the current architecture and controls posture, read the Security and data handling page.

Your data is encrypted

Application traffic and provider connections use TLS. The database and object storage providers encrypt stored data, and Nebula wraps each user signing key with AES-256-GCM using a separate key supplied to the running service.

Where processing happens

Application compute is pinned to Sydney. Operational records use managed Neon Postgres and document storage uses Cloudflare R2, with provider-managed encryption at rest. Document intelligence routes through approved AI providers and a session-bound model. Text inputs pass identifier redaction, customer content is covered by no-training terms, and native PDFs are available to models with native document capability.

Personal information is protected

Customer documents and extracted content are used only to provide the service, under terms that exclude model training, fine-tuning, and model improvement.

Personal details, phone numbers, email addresses, tax and identity numbers, are automatically redacted from text before it is sent to be read, and restored afterwards. Business registry numbers stay, because reading who owes what requires the parties and those numbers are public identifiers. Native PDFs are processed as complete documents under the same limited-purpose commitment.

You can request erasure of your personal information at any time, with a thirty-day grace period in case you change your mind. Erasure anonymises the account and selected name copies, but shared engagement, audit, and proof records may remain where counterparties, evidence, security, or legal duties require them. A Polygon transaction contains a hash. Nebula also retains the canonical preimage used to verify each proof and sends a signed canonical event payload to its operated Nebulad ledger. That payload can include user, engagement, and record identifiers, titles, descriptions, dates, and status. Source supporting evidence is represented by file hashes rather than source document files.

Standards that shape the controls

SOC 2 is an independent CPA examination of controls relevant to security, availability, processing integrity, confidentiality, and privacy. Nebula maps its control design and evidence to the AICPA Trust Services Criteria used in that framework.

The Australian Government Information Security Manual, or ISM, is the Australian Signals Directorate's risk-based cyber security framework for protecting systems and data. Nebula uses the ISM to structure its control and data-handling matrix. IRAP is the pathway through which an ASD-endorsed assessor evaluates an agreed system boundary against applicable ISM controls. Where a procurement requires that evidence, the deployment scope, assessor, and authorisation decision are agreed with the customer.

Nebula's privacy program is designed around mechanisms in the Australian Privacy Principles, including purpose-limited processing, disclosure of overseas processing, access and correction channels, and erasure. Read the Privacy Policy for the current commitments. Customer assurance reviews map those mechanisms to the intended deployment, jurisdiction, and obligations.

A complete, checkable record

The shared authentication gate records admitted and denied API access. Defined engagement transitions and selected exports write their own audit records. A scheduled integrity check re-fetches confirmed anchors and raises an alert when it detects a hash mismatch.