Authentication and access
- Session-based authentication via Better Auth
- Two-factor authentication (TOTP)
- Passkeys (WebAuthn)
- SSO (OIDC / SAML) on enterprise plans
- Role-based access control within organizations
Where your data lives
The platform is hosted on AWS in the EU (Ireland), and all stored customer data lives there. Red-team scan simulation uses LLM processing via AWS Bedrock, and transactional email is delivered via Amazon SES. These processing paths are also disclosed in our Privacy Policy.
Data handling
- Agent traces and outputs are retained according to your workspace's retention settings.
- We recommend running red-team scans against staging agents with synthetic data, not production systems holding real user data.
- You can request full deletion of your organization's data via harsh@nyraxis.io.
- Self-hosted deployments keep all data inside your own infrastructure.
We scan ourselves
Our own demo and internal agents are continuously tested with the same red-team engine we ship to customers. We dogfood the product; findings from our own scans feed directly into the attack library.
Compliance roadmap
SOC 2 Type I is planned. We are not certified today, and we won't claim otherwise. If your procurement process requires specific attestations, talk to us and we'll tell you exactly where we stand.
Responsible disclosure
Found a vulnerability in Nyraxis itself? We want to hear from you. Report it to harsh@nyraxis.io with the subject "Security disclosure". Please give us a reasonable window to investigate and remediate before public disclosure. We commit to acknowledging reports promptly and keeping you updated.