NSOffice.AI by Network Science
Get a Demo

Security at NSOffice.AI

How we protect your organization's data

Security is built into every layer of the NSOffice.AI platform — from how we store your data, to how every AI request is screened, to how we govern the models we use. This page summarizes our approach; if you need more detail for a security review, see the contact note at the end.

1. Information Security Management

Our Information Security Management System (ISMS) is built to the ISO/IEC 27001:2022 standard, covering our people, processes, and technology, and is subject to independent certification review. It's supported by a documented set of internal security policies covering access control, incident management, business continuity, secure development, and AI governance, each reviewed on a regular cycle.

2. Data Residency, by Design

  • Your organization's data is stored and processed within its own Regional Data Plane: Indian organizations' data stays on servers located in India; UK organizations' data stays on servers located in the United Kingdom. We do not move stored data between these regions.
  • When the platform retrieves information from a connected business system to answer a request, it does so in real time, rather than keeping a separate long-term copy of that data outside your region.

3. Multi-Tenant Isolation

NSOffice.AI is a multi-tenant platform: each customer organization's data is held in a logically isolated environment, separate from every other customer's. Access to your organization's environment is scoped to your organization's own authenticated users and administrators.

4. Identity and Access Management

  • Enterprise authentication options include passwordless sign-in, multi-factor authentication, and single sign-on through your organization's identity provider.
  • Access within the platform is governed by role-based permissions, so users see only what their role authorizes.
  • Administrative access to production systems follows the principle of least privilege and is logged for audit purposes.

5. Encryption

Data is encrypted in transit using industry-standard protocols, and at rest using strong encryption, across all storage systems that hold Customer Content.

6. Guardrails on Every AI Request

Before any request reaches an underlying AI model, it passes through our guardrails layer, which is designed to:

  • Detect and redact personal data, so it is not unnecessarily exposed to an AI model;
  • Screen for prompt injection and other attempts to manipulate the platform's AI behavior; and
  • Check content against safety and content-moderation rules before a response is generated or an action is taken.

This applies to every AI-assisted feature, regardless of which underlying AI model handles the request.

7. Network and Infrastructure Security

Our infrastructure runs on a leading cloud provider and is protected by a layered set of network defenses, including a web application firewall, DDoS protection, and network segmentation that isolates production systems from the public internet. Administrative access to infrastructure is restricted to authorized personnel through a dedicated, access-controlled channel, rather than direct exposure.

8. Continuous Monitoring and Threat Detection

  • Our environment is monitored 24/7 by a dedicated security operations function.
  • We run continuous automated security scanning of our cloud infrastructure to catch misconfigurations and emerging vulnerabilities early.
  • Security-relevant events are logged, correlated, and reviewed on an ongoing basis.

9. Secure Software Development

Changes to the platform go through code review and automated security testing before release, following a formal change management process that includes a documented approval step and a pre-change backup requirement for significant changes.

10. AI Model Governance

  • Every AI model used on the platform — whether from a third-party provider or self-hosted — goes through a risk assessment and approval process before it's used in production.
  • Model performance and safety behavior are monitored on an ongoing basis, with human oversight built into the approval and monitoring process.
  • Our AI governance practices are aligned with ISO/IEC 42001, the international AI management system standard.

11. Business Continuity

The platform is architected for resilience within each operating region, including redundant infrastructure and regular backups, with a documented recovery process that is tested periodically.

12. Data Retention and Deletion

When your organization's relationship with us ends, or when data is deleted within the platform, it enters a 30-day recoverable period, followed by permanent deletion within 180 days across all systems, including AI-derived memory data.

13. Incident Response

We maintain a documented incident response process so that security events are detected, contained, and communicated to affected customers promptly. See our Data Processing Agreement for our breach notification commitments.

14. Reporting a Vulnerability

We welcome reports from security researchers acting in good faith. See our Vulnerability Disclosure Policy for how to report an issue.

Need more detail for your organization's security review? Contact customersupport@nsoffice.ai — we're happy to walk your team through our Data Processing Agreement, sub-processor list, and current certification status directly.

Security Overview | NSOffice.AI