Skip to content
NEURA PARSE

00Trust & security

Public controls for product-grade automation

This page separates published controls, programs in progress, design references, and customer-specific obligations. SOC 2 and ISO 27001 are shown as in progress—not completed certifications.

SOC 2 · IN PROGRESS · ISO 27001 · IN PROGRESS · GDPR POLICY PATH · TLS 1.3 TARGET · SECURITY CONTACT · STATUS-LABELLED

Trust operations

Controls mapped to evidence paths

NP

01

SOC 2 Type II

02

GDPR coverage

03

TLS 1.3 / AES-256

01

Policy routes published

02

DPA and privacy review path

03

Security evidence queue

04

Incident response owner

Baseline

Buyer review and evidence surface

Published
Standards tracked
13
In transit
TLS 1.3
At rest
AES-256
Security reporting route
Public
Modern enterprise data center corridor with high-density server racks

Trust operations

A professional trust view for enterprise buyers: encryption, access control, audit evidence, incident response, and governance controls mapped into one operating model.

TLS 1.3 / AES-256
Audit evidence
Governance controls
Published control model
  1. 01

    Least privilege · MFA

  2. 02

    Published control routes

  3. 03

    Reviewable event evidence

  4. 04

    Named security owner

Transport
TLS 1.3 target
Storage
AES-256 target
Posture
Status-labelled

01Operational commitments

These are the headline controls currently visible across the public security, privacy, and legal pages, presented as reviewable evidence paths.

01In progress

Control programme

SOC 2 Type II

Security, availability, and confidentiality controls with evidence collection in motion.

02Published

Privacy routes

GDPR coverage

Public privacy policy, DPA request path, and DPO contact routes for buyer review.

03Product-scoped

Data protection

TLS 1.3 / AES-256

Published transport and at-rest encryption targets; configuration and evidence are verified for each product and deployment.

02Security practices

The public security policy outlines concrete practices rather than abstract promises. These are the highest-signal themes.

01
  • TLS 1.3 for data in transit
  • AES-256 for data at rest
  • Encrypted databases and backups
02
  • MFA for administrative access
  • Least-privilege role-based access
  • Regular access reviews
03
  • Traffic and anomaly monitoring under the product-specific operating model
  • Firewall and DDoS protections
  • Secure cloud infrastructure posture
04
  • Security-focused code reviews
  • Static analysis and dependency patching
  • Vulnerability scanning and patch management

03Compliance posture

The matrix below shows our current posture across security, privacy, AI governance, operational continuity, and sector-specific controls. Filter by category for the parts that matter to your procurement review.

Last reviewed 2026-07-12

SecurityPublic and service transport where supportedPublished control target; endpoint evidence available during review
SecurityCustomer data, model artifacts, and audit recordsPublished design control; deployment scope verified per product
SecurityService Organization ControlsProgramme in progress; no completed attestation claimed
SecurityInformation security management systemProgramme in progress; no certification claimed
OperationalPublished security contact and intake routesecurity@neuraparse.com is the public reporting channel
OperationalDetection, triage, containment, communication, and reviewEvidence and contractual response details are reviewed per service
PrivacyPrivacy notice, data-subject requests, and customer processing scopePolicy and legal request routes published; obligations assessed per role
PrivacyController, processor, subprocessors, retention, and transferCustomer-specific review through legal@neuraparse.com
AI GovernanceAI context, measurement, management, and governanceUsed as a design and assessment reference; not a certification
AI GovernanceDefense-AI lawfulness, accountability, traceability, reliability, governability, and biasUsed as a public requirements reference; no NATO certification claimed
AI GovernanceRole, risk classification, data, transparency, oversight, robustness, and monitoringLegal and product assessment required for each use case
Sector-specificPHI, intended use, clinical validation, QMS, and market authorizationCustomer- and product-specific pathway; no blanket HIPAA/FDA/CE claim
Sector-specificData classification, end use, parties, technology, and jurisdictionCase-by-case legal and customer review required
AlignedIn progressOn roadmapNot applicable

Need a specific attestation, DPA, or sub-processor list? Email security@neuraparse.com with the procurement contact and we'll route the right document.

Deeper review

Use the published contact routes for support, security, privacy, or a guided NowFlow demo tailored to your stack.