Security & trust

Governed autonomy, not black-box automation

NERVA is built for enterprises that must explain routing decisions to auditors, regulators, and their own operators — with evidence, policy gates, and tenant isolation.

Tenant isolation

Every request, decision, graph object, and audit event is scoped by tenant. Subdomain routing with session-bound context.

RBAC with eight roles

Platform admin, operator, triage lead, graph steward, auditor, requester — permissions enforced in middleware and server actions.

Constitutional policy gates

Routing cannot bypass NCL rules and policy evaluation. Low-confidence and insufficient-evidence states are first-class, not hidden.

Inspectable audit trail

Decision proposed, correction applied, connector sync, route approved — all events exportable as JSON/ZIP for procurement.

Sovereign & air-gap profiles

Regulated demo tenants enforce connector restrictions at runtime. Deployment supports VPC and sovereign profiles.

Secrets vault

Tenant-scoped connector credentials via encrypted secrets panel — not hardcoded in application config.

Procurement & investor packages

Signed evidence bundles, investor briefs, and walkthrough JSON — generated from live tenant state, not static PDFs.