Neura Parse

Public controls for product-grade automation

The current public NowFlow materials emphasize clear operational controls: TLS 1.3 in transit, AES-256 at rest, 24/7 monitoring, published privacy and legal routes, and trust signals including SOC 2, GDPR, and 99.9% SLA positioning.

TLS 1.3 / AES-25624/7 monitoringSOC 2 / GDPR / 99.9% SLA
Operational Signals
5 Active
S2

SOC 2

Type II controls

GD

GDPR

Privacy coverage

99

99.9% SLA

Uptime target

TL

TLS 1.3

AES-256 at rest

24

24/7 Monitoring

Detection & response

Live
Modern enterprise data center corridor with high-density server racks

A professional trust view for enterprise buyers: encryption, access control, audit evidence, incident response, and governance controls mapped into one operating model.

TLS 1.3 / AES-256
Audit evidence
Governance controls
Live model
1

Identity

Zero telemetry

2

Policy

Encrypted comms

3

Audit

Review gates

4

Evidence

Zero telemetry

Signal

Zero telemetry

Signal

Encrypted comms

Signal

Review gates

These are the headline commitments and controls currently visible across the NowFlow home, security, privacy, and legal pages.

Data Protection

TLS 1.3 for data in transit, AES-256 for stored data, and encryption-focused handling across workflows and services.

Access Controls

Administrative MFA, least-privilege role-based access, periodic reviews, and secure session management.

Monitoring & Response

24/7 monitoring, incident procedures, communication plans, and tested recovery workflows are described publicly.

Trust Signals

SOC 2 Type II, GDPR, CCPA, ISO 27001 in progress, and 99.9% uptime SLA appear across public materials.

The public security policy outlines concrete practices rather than abstract promises. These are the highest-signal themes.

Encryption

  • TLS 1.3 for data in transit
  • AES-256 for data at rest
  • Encrypted databases and backups

Access & Identity

  • MFA for administrative access
  • Least-privilege role-based access
  • Regular access reviews

Monitoring & Infrastructure

  • 24/7 monitoring of traffic and anomalies
  • Firewall and DDoS protections
  • Secure cloud infrastructure posture

Secure Development

  • Security-focused code reviews
  • Static analysis and dependency patching
  • Vulnerability scanning and patch management

The matrix below shows our current posture across security, privacy, AI governance, operational continuity, and sector-specific controls. Filter by category for the parts that matter to your procurement review.

Last reviewed 2026-05-10

SecurityAll public endpoints + service-to-serviceDefault cipher policy; HSTS enforced
SecurityCustomer data, model weights, audit logsFIPS-grade primitives; key rotation policy
SecurityService Organization Controls (TSC)Programme initiated; auditor selected
SecurityInformation security management systemStatement of Applicability drafted
SecurityExternal + internal application + infraAnnual third-party tests; report on request
SecuritySIEM + detection-as-code + on-call rotationPagerDuty + signed incident timeline
PrivacyPersonal data of EU residentsDPIA template; DPO contact published
PrivacyPersonal data of UK residentsICO-registered controller / processor
PrivacyCalifornia consumer privacyRight-to-know + delete pathways
PrivacyCustomer-facing data processing addendumStandard DPA + current sub-processor list
AI GovernanceHigh-risk AI obligations (Annex III)Risk register + human-oversight design
AI GovernanceAI management systemTargeted alongside ISO 27001 expansion
AI GovernanceAI RMF 1.0 alignmentMap / Measure / Manage controls in place
AI GovernanceModel documentation + training data lineageed25519-signed manifests via qmesh substrate
OperationalSecurity@neuraparse.com response timeAcknowledged < 24 h; remediation SLA
OperationalDetection → containment → notificationTested quarterly; customer notification SLA
OperationalRPO 24 h · RTO 4 hEncrypted off-site backups; restore drills
OperationalBC + DR plan with annual exerciseReviewed annually; sponsor at exec level
Sector-specificPHI handling for healthcare customersBAA available; design-aware controls
Sector-specificDefense / dual-use technologyCompliance review on case-by-case basis
Sector-specificMedical device developmentAligned to customer-led pathways
AlignedIn progressOn roadmapNot applicable

Need a specific attestation, DPA, or sub-processor list? Email security@neuraparse.com with the procurement contact and we'll route the right document.

The live public stack includes dedicated pages for privacy, terms, cookies, DPA, security, and contact routing. That makes the trust surface easier to inspect and easier to use.

Privacy policy

Published with GDPR and CCPA framing, Google API data-use notes, and direct privacy contacts.

Legal hub

One public place to reach privacy, terms, cookies, DPA, and security policy material.

Incident response

The public security policy lists response procedures, recovery steps, and breach-notification commitments.

Enterprise routes

Custom paperwork, security questionnaires, and compliance follow-ups are routed through dedicated contact paths.

Use the published contact routes for support, security, privacy, or a guided NowFlow demo tailored to your stack.