Security & Privacy, by Design.

Strong encryption, least-privilege access, and a privacy-first architecture—so your data stays yours.

🔒
AES-256-GCM

Encrypted secrets vault

🔐
TLS 1.3

In transit, with HSTS

🌐
GDPR & CCPA

Data rights honored

🛡️
You Own Your Data

Export or delete anytime

Data Security & Encryption

Encryption at Every Layer

🔐 In Transit
  • TLS 1.3: All traffic over HTTPS with modern ciphers
  • Perfect Forward Secrecy: Ephemeral keys per session
  • HSTS & OCSP stapling: Strict transport security enforced at the edge
  • Least-privilege access: Scoped, per-tenant access controls
💾 At Rest
  • AES-256-GCM secrets vault: Authenticated encryption for credentials and sensitive records
  • Field-level encryption: Sensitive database fields (API keys, 2FA secrets) encrypted at the application layer
  • Key management: Encryption keys held in a hardened vault with rotation—never in source control
  • Per-tenant isolation: Row-level security on provisioned databases

Your Data, Your Control

You own your content. Transient files used only to produce a result are deleted within 24 hours; anything you save stays until you delete it.

Transient processing

Files used only to generate a result are removed within 24 hours of processing.

Saved content stays yours

Files, projects, and data you choose to save are retained until you delete them or close your account.

Delete anytime

Remove files, projects, or your whole account from the dashboard. Account deletion has a 30-day recovery window, then data is purged.

Your Control: Export your data or delete it anytime from the dashboard. See our Privacy Policy for full retention details.

Access Control & Authentication

Multi-Layer Authentication

User Authentication
  • Multi-Factor Authentication (MFA): Required for Enterprise tier
  • SSO Integration: SAML 2.0 and OAuth 2.0 support
  • Password Requirements: Minimum 12 characters, complexity enforced
  • Session Management: Auto-logout after 30 minutes inactivity
API Security
  • API Key Encryption: Keys encrypted with user-specific salts
  • Rate Limiting: Prevents brute-force attacks
  • IP Whitelisting: Restrict access to trusted networks (Enterprise)
  • Audit Logging: Every API call logged with timestamp and user

Role-Based Access Control (RBAC)

Fine-grained permissions ensure users only access what they need.

Role Permissions Use Case
Admin Full system access, user management, billing IT administrators, account owners
Manager View all projects, assign tasks, export reports Legal team leads, business analysts
Analyst Process documents, view assigned projects Paralegals, junior analysts, researchers
Viewer Read-only access to reports and insights Stakeholders, external auditors

Compliance & Privacy

Independent Security Reviews

What it means: We continuously test the platform against real attack classes—not just claim it's safe.

  • Structured exploit-resistance audits (IDOR, injection, tenant isolation)
  • Per-tenant isolation with row-level security, verified by tests
  • Encrypted secrets vault, distributed rate limiting, and audit logging
  • Documented security practices and review process

A formal SOC 2 program is on our roadmap; we'll publish an attestation here only once it's independently completed.

GDPR & CCPA — Your Data Rights

What it means: We honor the data-protection rights GDPR and CCPA give you.

  • Access & export: Export your profile and account data
  • Deletion: Delete files, projects, or your whole account (30-day recovery window, then purged)
  • Consent: Explicit opt-in for SMS and marketing communications
  • No sale of your data: We don't sell your personal information

See our Privacy Policy, Sub-processors, and Data Processing Agreement for full details.

Working toward formal certification

We're building toward independently-audited certifications, starting with SOC 2, and evaluating frameworks like ISO 27001 and HIPAA for regulated customers. We will list a certification here only after it's been independently verified—never before. Payments are processed by Stripe, a PCI-DSS Level 1 service provider; NeuroGen never stores raw card data.

Infrastructure & Network Security

Cloud Infrastructure

Hosted on hardened Linux infrastructure behind a TLS-terminating reverse proxy, with automated backups and monitoring.

Availability
  • Continuous uptime & health monitoring
  • Automated health checks
  • Rapid redeploy on failure
Monitoring
  • Automated system monitoring
  • Real-time error alerting (Sentry)
  • Regular security patching
Backup & Recovery
  • Automated daily database backups
  • Retained on a rolling schedule
  • Documented recovery process

Network Security

Perimeter Defense
  • Application-layer protections: Parameterized queries, output sanitization, and a Content-Security-Policy block common attacks (SQL injection, XSS)
  • Distributed rate limiting: Throttles abuse and brute-force attempts
  • Restricted host: Firewalled, minimal open ports
  • Strict firewall rules: Default-deny network access
Internal Security
  • Network Segmentation: Isolated zones for different services
  • Least Privilege Access: Minimal permissions for each service
  • Encrypted Inter-Service Communication: TLS for all internal traffic
  • Regular Penetration Testing: Quarterly security assessments

Audit Trails & Transparency

Complete Audit Logging

Every action in NeuroGen is logged for accountability and compliance.

What We Log
  • User authentication (logins, logouts, failed attempts)
  • Document uploads and processing
  • AI agent decisions with confidence scores
  • Data exports and downloads
  • API calls and responses
  • Configuration changes
Log Security
  • Immutable Logs: Cannot be altered or deleted
  • Encrypted Storage: Logs encrypted at rest
  • Retention: 7 years for compliance
  • Tamper Detection: Cryptographic verification
  • Access Control: Only authorized personnel

Explainable AI Decisions

Unlike "black box" AI systems, NeuroGen provides transparency into how AI agents reach conclusions.

  • Decision Paths: See which factors influenced each agent's analysis
  • Confidence Scores: Quantified certainty for every prediction
  • Cross-Validation Details: How agents agreed or disagreed
  • Human Review Flags: When AI isn't confident, it tells you
Why this matters: In legal discovery, regulatory compliance, and high-stakes business decisions, you need to defend your AI-assisted conclusions. NeuroGen gives you the evidence trail to do it.

Incident Response & Security Team

24/7 Security Operations Center

Dedicated security team monitoring for threats around the clock.

Detection
  • Automated error & anomaly monitoring (Sentry)
  • Rate-limit and abuse alerting
  • Audit logging of sensitive actions
Response
  • Documented incident-handling process
  • Rapid investigation and containment
  • Fixes prioritized and shipped promptly
Communication
  • Affected-user notification for confirmed breaches (consistent with GDPR's 72-hour guidance)
  • Transparent incident summaries
  • Post-incident analysis and remediation

Security Contact & Reporting

Found a security vulnerability? We appreciate responsible disclosure.

  • Email: security@neurogen.ai (monitored 24/7)
  • PGP Key: Available for encrypted communication
  • Bug Bounty: Rewards for verified security issues
  • Response Time: Initial response within 24 hours

Enterprise Security Options

On-Premise Deployment

Run NeuroGen in your own data center for maximum control.

  • Complete data sovereignty
  • Integration with existing security infrastructure
  • Custom compliance requirements
  • Dedicated support and maintenance

Available for Enterprise tier with annual contract

Dedicated Deployment

For Enterprise customers with specific isolation or data-residency needs, we offer dedicated deployment options—let's scope what you need.

  • Dedicated database instance
  • Custom security controls
  • Data-residency options
  • Scoped to your requirements

Available on request for Enterprise tier — talk to us.

Questions About Security?

Our security team is here to answer your questions and discuss custom requirements.

Contact Security Team View Enterprise Plans
Connecting