Skip to main content

Enterprise readiness

What happens to your work inside Nebula.

Sixteen questions, each with one sentence that is true today and one boundary sentence that travels with it.

ENTERPRISE READINESS

A detection product infers what happened to your data, and Nebula does not need to infer because it records.

Provenance, attribution, classification, access and retention are properties of the record itself.

Procurement answers

Current answers and their boundaries.

  1. 01Identity and single sign-on

    Current answer

    Nebula supports password sign-in and, when configured, organisation-required sign-in through Microsoft Entra ID or Google Workspace with provider and tenant binding.

    Required boundary

    SAML and generic identity-provider metadata are not supported, and current production activation has not been proved by this repository evidence.

  2. 02Provisioning and deprovisioning

    Current answer

    Nebula implements SCIM v2 user creation, listing, reading, updating, deactivation and organisation-access removal behind an enabled organisation identity policy and a current token.

    Required boundary

    Production activation is not proved, removal ends organisation membership rather than deleting the underlying user, and privileged memberships require an administrator workflow.

  3. 03Tenant isolation

    Current answer

    The standard service is multi-tenant and applies organisation, engagement and role checks to the cited protected paths.

    Required boundary

    The service uses shared application data stores, not infrastructure dedicated to each customer, and the evidence is not a route-by-route proof of every access path.

  4. 04Encryption in transit

    Current answer

    Nebula configures HSTS for application responses and uses HTTPS for the cited connected-service endpoints.

    Required boundary

    No current external scan or complete connected-service transport record proves the live protocols and ciphers for every path.

  5. 05Encryption at rest and key custody

    Current answer

    Nebula uses authenticated application-level encryption for signing private keys and multi-factor authentication secrets; database and object storage at-rest protection remains an unverified provider boundary.

    Required boundary

    Current provider algorithms, backup coverage, account settings and key-custody evidence are not established, and customer-managed keys are not supported.

  6. 06Data residency

    Current answer

    Nebula configures application compute for Sydney.

    Required boundary

    That setting does not prove the region that served a request and is not an end-to-end Australian data-residency guarantee across database, object storage, model processing, support, telemetry and connected services.

  7. 07Retention and deletion on demand

    Current answer

    Nebula provides project-scoped retention controls and a user erasure path with a 30-day grace period.

    Required boundary

    No single operation is proved to export or delete every organisation data class across application records, providers and backups, and shared audit, engagement or public-proof records can remain.

  8. 08Audit and access records

    Current answer

    Nebula records defined access and business actions and provides project and personal export paths for the records those paths cover.

    Required boundary

    Some logging is best effort, not every read or field change is covered, and an organisation cannot yet export one complete audit trail including staff access.

  9. 09Subprocessors

    Current answer

    Nebula maintains a versioned draft inventory of the services that may process data for the standard hosted service.

    Required boundary

    The register is not yet approved for operative publication, and current entity, terms, region, retention, transfer and activation checks remain incomplete for some paths.

  10. 10Incident response

    Current answer

    Nebula has a privacy-breach register and assessment workflow for recording and determining reported privacy events.

    Required boundary

    Named responder coverage, verified emergency contacts, non-privacy incident handling, deadline alerts, a tested exercise and restoration evidence are not operating as one proved response capability.

  11. 11Vulnerability management

    Current answer

    Nebula schedules dependency updates and uses locked dependencies, compilation and automated tests in its delivery workflow.

    Required boundary

    Central secret scanning, static and dynamic security scanning, a current vulnerability report, completed disclosure intake and a staffed security operations capability are not proved.

  12. 12Penetration testing

    Current answer

    Not yet. Nebula has no recorded independent penetration test.

    Required boundary

    No scope, report, remediation record or independent retest is available to provide.

  13. 13Certification and independent assurance

    Current answer

    Not yet. Nebula is not substantiated as holding an independent security certification, attestation or government assessment.

    Required boundary

    Its control design is mapped to the SOC 2 Trust Services Criteria and informed by the ISM, but a mapping is not an examination, certificate, assessment or authority to operate.

  14. 14Model processing boundary

    Current answer

    Nebula routes model processing through one sanctioned application boundary, applies pattern-based redaction to text inputs, sanitises provider errors, records explicit call metadata and prevents a model response from directly authorising a material action.

    Required boundary

    Native PDF bytes and file names are not covered by text redaction, redaction can be disabled by deployment configuration, current account terms and activation are not proved, and customer classification does not yet govern model routing.

  15. 15Data loss prevention

    Current answer

    No. Nebula is not a data loss prevention product.

    Required boundary

    Nebula does not inspect or control a customer's wider endpoints, networks, cloud stores or exfiltration channels.

  16. 16Data security posture management

    Current answer

    No. Nebula is not a data security posture management product.

    Required boundary

    Nebula does not discover and score a customer's external data estate or cloud-security posture.