跳至主要内容

信任与安全

信任中心

关于 Neurixmedia、Neurix Core 和 Neurix One 的安全、隐私与供应商准备信息。

This Trust Center summarizes implemented controls, partial controls, planned controls, and explicit non-claims. It is not a certification statement.

15 implemented2 partial2 planned

Last updated: June 15, 2026

Security

Security

Authentication boundaries, session protection, and operational access controls.

Implemented control

Protected admin operations

Admin routes require authenticated staff sessions with module permissions.

  • Module-based read/write guards on admin pages.
  • Admin login separated from client portal login.
  • No intentional public exposure of secrets in responses.
Implemented control

Client portal session boundaries

Invited client users access portal sections through authenticated sessions.

  • Portal routes require session validation.
  • Legacy /client namespace shares portal session guards.
  • Security settings available from portal profile area.
Implemented control

Hashed invite tokens

Tenant invitations use hashed tokens; raw tokens are not returned in list APIs.

  • Single-use invite acceptance flow.
  • Admin list/detail responses omit raw invite tokens.

Tenant isolation

Tenant isolation

Database and application isolation for multi-tenant client data.

Implemented control

Postgres row-level security (RLS)

Tenant-scoped tables enforce client isolation at the database layer.

  • RLS policies on tenant-scoped Foundation models including Membership and Subscription.
  • Admin operations use controlled bypass paths with audit awareness.
  • Platform tenant groundwork for shared infrastructure rows.
Implemented control

Membership tenant binding

Membership rows link users to clients for portal scope resolution.

  • Membership backfill completed in M3.1E.
  • Portal scope derives from membership, not payment provider callbacks.
Implemented control

Default-deny portal entitlements

Portal sections require explicit entitlement keys; billing does not auto-unlock access.

  • Internal Subscription records map to entitlement keys.
  • Payment provider webhooks do not directly unlock portal sections.
  • Resolver checks subscription-backed entitlements server-side.

Identity & access

Identity & access

Identity provider readiness, admin permissions, and access governance.

Partially implemented

Keycloak as target identity provider

Keycloak OIDC scaffold is present; activation remains feature-flagged.

  • KEYCLOAK_ENABLED gate controls activation attempts.
  • Placeholder env values block activation until founder configures production IdP.
  • Credentials login remains available when Keycloak is disabled.
Implemented control

Role and module access control

Admin module permissions gate sidebar visibility and page access.

  • Per-module read/write permission checks.
  • Team & users administration for staff accounts.

AI governance

AI governance

Scoped public assistant behavior and server-side provider configuration.

Implemented control

Scoped public AI assistant

Public assistant is FAQ-first and limited to Neurixmedia-approved topics.

  • No regulated professional advice (medical, legal, financial, immigration).
  • Conversation data handling described in Privacy Policy.
  • Admin-configurable knowledge, FAQs, and tool settings.
Implemented control

Server-side AI provider configuration

Model provider keys remain server-side; not exposed to browsers.

  • API routes proxy assistant operations.
  • Secret rotation checklist documented for operators (M0).

Data handling

Data handling

Hosting disclosure, privacy policies, and data category transparency.

Partially implemented

Data hosting disclosure

Production hosting region depends on approved deployment configuration.

  • U.S. deployment region intended when configured for production.
  • Subprocessor list confirmed before production launch per contract.
  • No claim that all data is exclusively U.S.-stored until deployment is finalized.
Implemented control

Privacy policy and data categories

Public privacy disclosure covers forms, portal, and assistant data.

  • Privacy Policy, Terms, and Cookie Policy published.
  • Contact and brief form data used for inquiry response.

Audit logging

Audit logging

Structured audit events for foundation operations — no raw webhook payloads.

Implemented control

Foundation audit events

Membership, invitation, billing, and portal actions emit structured audit events.

  • Audit action registry for Foundation phases.
  • Billing view and mutation attempts logged when enabled.
  • No raw webhook payloads in audit logs.

Billing & payment safety

Billing & payment safety

Checkout safeguards, no card storage, and internal Subscription as source-of-truth.

Implemented control

Checkout disabled by default

Billing checkout, admin writes, and client portal billing UI are feature-flagged off.

  • BILLING_CHECKOUT_ENABLED=false and BILLING_CHECKOUT_MODE=disabled in .env.example.
  • Live checkout mode blocked in application policy.
  • No live Stripe or Paddle API calls in default configuration.
Implemented control

No card data storage

Neurixmedia application code does not store card numbers or CVV data.

  • Future checkout flows delegate card capture to payment providers.
  • Internal Subscription remains entitlement source-of-truth.

Incident readiness

Incident readiness

Operator checklists and published security contact paths.

Implemented control

Secret rotation checklist

Operator checklist for rotating compromised or stale secrets (M0).

  • Documented at docs/security/secret-rotation-m0.md.
  • Categories include auth, database, AI, billing, and webhook secrets.
Implemented control

Security contact path

Published contact channel for security and privacy inquiries.

  • contact@neurixmedia.com for security or privacy questions.
  • Formal incident response SLAs only when contractually agreed.

Current limitations

Honest gaps and in-progress items — not hidden and not softened.

Third-party audit not yet completed

Formal SOC 2 / ISO audits are planned controls, not current claims.

  • Certification badges are not displayed on this website.
  • Formal documents shared only when verified and approved for an engagement.

Production deployment finalization

Some hosting and subprocessor details finalize at production cutover.

  • Final subprocessor list confirmed before launch.
  • Data residency statements updated when deployment region is locked.

Strategic alignment

UAE AI 2031 strategic alignment

Neurixmedia aligns product and governance language with themes from the UAE National Strategy for Artificial Intelligence 2031. This describes our design intent — not government endorsement or regulatory approval.

Responsible AI

FAQ-first public assistant, scoped use cases, and human review paths for sensitive topics.

Governance

Admin-configurable AI settings, audit-friendly operations, and default-deny portal entitlements.

Talent & readiness

Documented foundation phases (M0–M5) so teams can onboard with clear control expectations.

Secure AI adoption

Server-side provider keys, no client-side secret exposure, and scaffold-only billing until founder activation.

Efficiency & service quality

Structured knowledge, promotions, and assistant tooling to improve response quality without overclaiming automation.

Strategic alignment only — not UAE government endorsement, certification, or approval.

What we do not claim

  • SOC 2: Not claimed as certified on this website. Third-party audit not yet completed. Formal status is not yet certified.
  • ISO 27001: Not claimed as certified. Formal certification not yet completed.
  • PCI DSS certification: Not claimed. Card data is not stored by Neurixmedia application code.
  • HIPAA: Not claimed as compliant for Neurixmedia platform controls.
  • GDPR certification: GDPR is not a certification we claim. Privacy practices are described in our Privacy Policy.
  • Official UAE approval: No government endorsement or approval is claimed.

Security contact

For security or privacy questions, contact

We review good-faith reports during business hours. This is not a 24/7 incident response hotline unless separately contracted.