Security & Privacy, by Design.
Strong encryption, least-privilege access, and a privacy-first architecture—so your data stays yours.
AES-256-GCM
Encrypted secrets vault
TLS 1.3
In transit, with HSTS
GDPR & CCPA
Data rights honored
You Own Your Data
Export or delete anytime
Data Security & Encryption
Encryption at Every Layer
🔐 In Transit
- TLS 1.3: All traffic over HTTPS with modern ciphers
- Perfect Forward Secrecy: Ephemeral keys per session
- HSTS & OCSP stapling: Strict transport security enforced at the edge
- Least-privilege access: Scoped, per-tenant access controls
💾 At Rest
- AES-256-GCM secrets vault: Authenticated encryption for credentials and sensitive records
- Field-level encryption: Sensitive database fields (API keys, 2FA secrets) encrypted at the application layer
- Key management: Encryption keys held in a hardened vault with rotation—never in source control
- Per-tenant isolation: Row-level security on provisioned databases
Your Data, Your Control
You own your content. Transient files used only to produce a result are deleted within 24 hours; anything you save stays until you delete it.
Transient processing
Files used only to generate a result are removed within 24 hours of processing.
Saved content stays yours
Files, projects, and data you choose to save are retained until you delete them or close your account.
Delete anytime
Remove files, projects, or your whole account from the dashboard. Account deletion has a 30-day recovery window, then data is purged.
Access Control & Authentication
Multi-Layer Authentication
User Authentication
- Multi-Factor Authentication (MFA): Required for Enterprise tier
- SSO Integration: SAML 2.0 and OAuth 2.0 support
- Password Requirements: Minimum 12 characters, complexity enforced
- Session Management: Auto-logout after 30 minutes inactivity
API Security
- API Key Encryption: Keys encrypted with user-specific salts
- Rate Limiting: Prevents brute-force attacks
- IP Whitelisting: Restrict access to trusted networks (Enterprise)
- Audit Logging: Every API call logged with timestamp and user
Role-Based Access Control (RBAC)
Fine-grained permissions ensure users only access what they need.
| Role | Permissions | Use Case |
|---|---|---|
| Admin | Full system access, user management, billing | IT administrators, account owners |
| Manager | View all projects, assign tasks, export reports | Legal team leads, business analysts |
| Analyst | Process documents, view assigned projects | Paralegals, junior analysts, researchers |
| Viewer | Read-only access to reports and insights | Stakeholders, external auditors |
Compliance & Privacy
Independent Security Reviews
What it means: We continuously test the platform against real attack classes—not just claim it's safe.
- Structured exploit-resistance audits (IDOR, injection, tenant isolation)
- Per-tenant isolation with row-level security, verified by tests
- Encrypted secrets vault, distributed rate limiting, and audit logging
- Documented security practices and review process
A formal SOC 2 program is on our roadmap; we'll publish an attestation here only once it's independently completed.
GDPR & CCPA — Your Data Rights
What it means: We honor the data-protection rights GDPR and CCPA give you.
- Access & export: Export your profile and account data
- Deletion: Delete files, projects, or your whole account (30-day recovery window, then purged)
- Consent: Explicit opt-in for SMS and marketing communications
- No sale of your data: We don't sell your personal information
See our Privacy Policy, Sub-processors, and Data Processing Agreement for full details.
Working toward formal certification
We're building toward independently-audited certifications, starting with SOC 2, and evaluating frameworks like ISO 27001 and HIPAA for regulated customers. We will list a certification here only after it's been independently verified—never before. Payments are processed by Stripe, a PCI-DSS Level 1 service provider; NeuroGen never stores raw card data.
Infrastructure & Network Security
Cloud Infrastructure
Hosted on hardened Linux infrastructure behind a TLS-terminating reverse proxy, with automated backups and monitoring.
Availability
- Continuous uptime & health monitoring
- Automated health checks
- Rapid redeploy on failure
Monitoring
- Automated system monitoring
- Real-time error alerting (Sentry)
- Regular security patching
Backup & Recovery
- Automated daily database backups
- Retained on a rolling schedule
- Documented recovery process
Network Security
Perimeter Defense
- Application-layer protections: Parameterized queries, output sanitization, and a Content-Security-Policy block common attacks (SQL injection, XSS)
- Distributed rate limiting: Throttles abuse and brute-force attempts
- Restricted host: Firewalled, minimal open ports
- Strict firewall rules: Default-deny network access
Internal Security
- Network Segmentation: Isolated zones for different services
- Least Privilege Access: Minimal permissions for each service
- Encrypted Inter-Service Communication: TLS for all internal traffic
- Regular Penetration Testing: Quarterly security assessments
Audit Trails & Transparency
Complete Audit Logging
Every action in NeuroGen is logged for accountability and compliance.
What We Log
- User authentication (logins, logouts, failed attempts)
- Document uploads and processing
- AI agent decisions with confidence scores
- Data exports and downloads
- API calls and responses
- Configuration changes
Log Security
- Immutable Logs: Cannot be altered or deleted
- Encrypted Storage: Logs encrypted at rest
- Retention: 7 years for compliance
- Tamper Detection: Cryptographic verification
- Access Control: Only authorized personnel
Explainable AI Decisions
Unlike "black box" AI systems, NeuroGen provides transparency into how AI agents reach conclusions.
- Decision Paths: See which factors influenced each agent's analysis
- Confidence Scores: Quantified certainty for every prediction
- Cross-Validation Details: How agents agreed or disagreed
- Human Review Flags: When AI isn't confident, it tells you
Incident Response & Security Team
24/7 Security Operations Center
Dedicated security team monitoring for threats around the clock.
Detection
- Automated error & anomaly monitoring (Sentry)
- Rate-limit and abuse alerting
- Audit logging of sensitive actions
Response
- Documented incident-handling process
- Rapid investigation and containment
- Fixes prioritized and shipped promptly
Communication
- Affected-user notification for confirmed breaches (consistent with GDPR's 72-hour guidance)
- Transparent incident summaries
- Post-incident analysis and remediation
Security Contact & Reporting
Found a security vulnerability? We appreciate responsible disclosure.
- Email: security@neurogen.ai (monitored 24/7)
- PGP Key: Available for encrypted communication
- Bug Bounty: Rewards for verified security issues
- Response Time: Initial response within 24 hours
Enterprise Security Options
On-Premise Deployment
Run NeuroGen in your own data center for maximum control.
- Complete data sovereignty
- Integration with existing security infrastructure
- Custom compliance requirements
- Dedicated support and maintenance
Available for Enterprise tier with annual contract
Dedicated Deployment
For Enterprise customers with specific isolation or data-residency needs, we offer dedicated deployment options—let's scope what you need.
- Dedicated database instance
- Custom security controls
- Data-residency options
- Scoped to your requirements
Available on request for Enterprise tier — talk to us.
Questions About Security?
Our security team is here to answer your questions and discuss custom requirements.
Contact Security Team View Enterprise Plans