Skip to main content

Enterprise readiness

What happens to your work inside Nebula

Sixteen questions, each with one sentence that is true today and one boundary sentence that travels with it.

ENTERPRISE READINESS

What Nebula supports, and what remains unproved

Each answer keeps the current capability beside the limit on its evidence.

Procurement answers

Current answers and their boundaries

  1. Identity and single sign-on

    Current answer

    Nebula supports password sign-in and, when configured, organisation-required sign-in through Microsoft Entra ID or Google Workspace with provider and tenant binding.

    Required boundary

    SAML and generic identity-provider metadata are not supported, and current production activation has not been proved by this repository evidence.

  2. Provisioning and deprovisioning

    Current answer

    Nebula implements SCIM v2 user creation, listing, reading, updating, deactivation and organisation-access removal behind an enabled organisation identity policy and a current token.

    Required boundary

    Production activation is not proved, removal ends organisation membership rather than deleting the underlying user, and privileged memberships require an administrator workflow.

  3. Tenant isolation

    Current answer

    The standard service is multi-tenant and applies organisation, engagement and role checks to the cited protected paths.

    Required boundary

    The service uses shared application data stores, not infrastructure dedicated to each customer, and the evidence is not a route-by-route proof of every access path.

  4. Encryption in transit

    Current answer

    Nebula configures HSTS for application responses and uses HTTPS for the cited connected-service endpoints.

    Required boundary

    No current external scan or complete connected-service transport record proves the live protocols and ciphers for every path.

  5. Encryption at rest and key custody

    Current answer

    Nebula uses authenticated application-level encryption for signing private keys and multi-factor authentication secrets; database and object storage at-rest protection remains an unverified provider boundary.

    Required boundary

    Current provider algorithms, backup coverage, account settings and key-custody evidence are not established, and customer-managed keys are not supported.

  6. Data residency

    Current answer

    Source configuration contains a syd1 Vercel Function-region instruction.

    Required boundary

    That source instruction does not prove the region that served a request and is not an end-to-end Australian data-residency guarantee across static delivery, edge execution, database, object storage, model processing, support, telemetry and connected services.

  7. Retention and deletion on demand

    Current answer

    Nebula provides project-scoped retention controls and a user erasure path with a 30-day grace period.

    Required boundary

    No single operation is proved to export or delete every organisation data class across application records, providers and backups, and shared audit, engagement or public-proof records can remain.

  8. Audit and access records

    Current answer

    Nebula records defined access and business actions and provides project and personal export paths for the records those paths cover.

    Required boundary

    Some logging is best effort, not every read or field change is covered, and an organisation cannot yet export one complete audit trail including staff access.

  9. Subprocessors

    Current answer

    Nebula maintains a dated provider register. It records provider-published entity, terms, region, retention and transfer information, separates those statements from Nebula account settings, and identifies unresolved supplier paths.

    Required boundary

    The register is not a contractual notice or blanket supplier approval. Accepted terms, selected regions and service activation remain unverified where stated.

  10. Incident response

    Current answer

    Nebula has a privacy-breach register and assessment workflow for recording and determining reported privacy events.

    Required boundary

    Named responder coverage, verified emergency contacts, non-privacy incident handling, deadline alerts, a tested exercise and restoration evidence are not operating as one proved response capability.

  11. Vulnerability management

    Current answer

    Nebula schedules dependency updates and uses locked dependencies, compilation and automated tests in its delivery workflow.

    Required boundary

    Central secret scanning, static and dynamic security scanning, a current vulnerability report, completed disclosure intake and a staffed security operations capability are not proved.

  12. Penetration testing

    Current answer

    Not yet. Nebula has no recorded independent penetration test.

    Required boundary

    No scope, report, remediation record or independent retest is available to provide.

  13. Certification and independent assurance

    Current answer

    Not yet. Nebula is not substantiated as holding an independent security certification, attestation or government assessment.

    Required boundary

    Its control design is mapped to the SOC 2 Trust Services Criteria and informed by the ISM, but a mapping is not an examination, certificate, assessment or authority to operate.

  14. Model processing boundary

    Current answer

    Nebula routes model processing through one sanctioned application boundary, applies pattern-based redaction to text inputs, sanitises provider errors, records explicit call metadata and prevents a model response from directly authorising a material action.

    Required boundary

    Native PDF bytes and file names are not covered by text redaction, redaction can be disabled by deployment configuration, current account terms and activation are not proved, and customer classification does not yet govern model routing.

  15. Data loss prevention

    Current answer

    No. Nebula is not a data loss prevention product.

    Required boundary

    Nebula does not inspect or control a customer's wider endpoints, networks, cloud stores or exfiltration channels.

  16. Data security posture management

    Current answer

    No. Nebula is not a data security posture management product.

    Required boundary

    Nebula does not discover and score a customer's external data estate or cloud-security posture.