
Nexa IntelligenceTRUST & SECURITY
Workforce intelligence, built inside your perimeter.
Nexa Intelligence runs inside your own Cloudflare account, your AWS, your Azure, or your on-premise environment. Everything the platform captures is yours. Respondent identifiers are stripped inside your tenant by a proxy you control, before any data leaves your perimeter, so Nexa never holds the original transcript or the entity list. You own the data, the schema, and the operational corpus. If you end the vendor relationship, the platform continues to run.
On the LLM side, our partner Anthropic provides a no-training compliance DPA on your data across every plan; Enterprise also gets a Zero Retention Policy on all LLM operations. On the voice and agent side, our partnership with ElevenLabs delivers No Training and No Data Retention across every plan. In accordance with Anthropic’s usage policy and compliance, we refuse military applications, surveillance of named individuals, and re-identification of respondents.
A DPA, a subprocessor list, and a security questionnaire are available on request through . Below, each section opens the in-depth detail on security, data management, and compliance. You can also at any time to quickly get to the specific information you need.
ARCHITECTURE AND DATA
In-Tenant Deployment
The platform installs inside your own Cloudflare account, your AWS, your Azure, or your on-premise environment. Data never leaves your perimeter to be processed. You control the substrate; we operate inside it.
Read more →Data Independence
You own the tenant, the data, the schema, the dashboards, and the AI agents that read against the corpus. The schema is documented and the corpus is portable. If you end the vendor relationship, your intelligence layer continues to run.
Read more →Security
Standard enterprise hygiene, run carefully. Encryption at rest and in transit, tenant-scoped secrets, per-environment key isolation, a documented incident response procedure, and a responsible disclosure program for security researchers.
Read more →Zero Retention Policy
All operations in the intelligence matrix run a Zero Data Policy. On top of no training, an in-tenant deployment keeps every piece of information inside your own account. Data resides in your infrastructure. The architecture is built to the controls behind HIPAA, SOC 2 Type II, Loi 25 Quebec, and GDPR, and runs inside the infrastructure you already certify.
Read more →PEOPLE AND CONSENT
Respondent Sovereignty
The workers who sit for an interview see the consent language before the conversation starts. You can extend the redaction list with anything specific to your business that should never appear in a transcript. When a worker revokes consent, every fact derived from their interview is automatically withdrawn from the intelligence layer.
Read more →Subprocessors
The third parties involved in processing your data, with role (capture, LLM inference, storage, observability), jurisdiction, contract type, and the specific data each one sees.
Read more →THE ENGINEERING SOURCE OF TRUTH