Vision Nexera

Security, data & IP

Your data. Your infrastructure. Your code, on payment.

The security-questionnaire answers before you send the questionnaire: where data lives, who touches it, how IP handover works, and the sub-processors we use, written honestly enough to be verified.

Principles

Four commitments we structurally uphold

Not policy statements: architectural defaults. If any of these were violated, the system would not work the way it does.

Your accounts, your infrastructure

We build on your cloud accounts, your git organisation, and your database wherever practicable. That means there is no hostage risk, no forced dependency, and rotation is trivial when we hand over.

Data stays inside your boundary

Embeddings, vector stores, logs, and application data live in your infrastructure by default. Model calls can route to providers with no-training data terms, or to self-hosted models where the case justifies it.

You own everything on payment

Code, prompts, pipelines, model artifacts, and documentation transfer on payment. Nothing we build ships with a licence key or a “call our team to rotate” dependency.

Least-privilege by construction

Access is per-engineer, scoped to the smallest useful set, and revocable in one place. Shared credentials, .env files in Slack, and long-lived tokens are outside our practice.

Data flow

Where your data goes, in the order it goes there

The trip your data takes from your system to a rendered answer, and back to deletion when you ask for it.

  1. 01 · Ingestion

    Your data enters through a boundary layer you own: typed contracts, structured payloads, explicit rejection for anything not in the schema. We never scrape your systems for training.

  2. 02 · Processing

    Retrieval, model calls, and validation happen inside your infrastructure by default. When a provider must be called (LLM APIs), we route only the minimum context necessary and log every request.

  3. 03 · Storage

    Embeddings, vector stores, and application state live in your database. We do not maintain shadow copies for our own use. Backups follow your retention policy, not ours.

  4. 04 · Retention & deletion

    Deletion is a supported operation, end-to-end, including in the retrieval index. When a customer invokes their data rights, the request is a straightforward code path, not an archaeology project.

  5. 05 · Handover

    On termination, access is revoked immediately, documentation is delivered, and any credentials we still hold are rotated and closed out: in writing, dated, and signed off.

Sub-processors

Who else touches your data, when, and under what terms

Every engagement pins its actual sub-processor list in the contract. This is the default set, with the terms we operate under.

ProviderRoleTerms
OpenAIModel provider (API)Enterprise / no-train tier where the engagement requires it
AnthropicModel provider (API)No-train by default; enterprise available
VercelHosting for this site + some client frontendsSOC 2 Type II
HetznerManaged VMs for k3s (our own products)ISO 27001; DPA available
MongoDB Atlas / PostgresManaged databases where clients electSOC 2 Type II
n8n (self-hosted)Workflow orchestration on client infrastructureSelf-hosted; no external data plane
Vapi / TwilioVoice + telephony (only where deployed)Per engagement DPA
ResendTransactional email (this site + optional client mailers)Standard DPA

Engagement-specific sub-processors (analytics vendors, CRMs, telephony carriers) are added to the list in writing before use. Any provider not listed here has not been engaged.

Report a vulnerability

Found something on this site or one of ours? Tell us directly.

Email hello@visionnexera.com with the details. We will acknowledge inside one business day, agree a disclosure timeline, and (with your permission) credit you on the fix.

Response commitments

Acknowledge
≤ 1 business day
Triage
≤ 3 business days
Fix Sev-1
Same day

FAQ

Everything we get asked before a contract

Where does our data go when we work with you?

It stays in your infrastructure by default. Application data, embeddings, vector stores, and logs live in your database and your cloud account. Model providers see only the minimum context needed for each call, and we route to no-train tiers or self-hosted models when the sensitivity of the case requires it.

Will our data be used to train models?

Not by us. We do not train on client data, ever. Provider training use depends on the tier; we default to no-train terms with OpenAI and Anthropic and document exceptions in the engagement contract. Self-hosted models eliminate the question entirely for cases that need it.

Who on your team gets access to our systems?

The specific engineers on your project, scoped to what they need, on their own credentials. No shared accounts, no “team” logins. Access is revocable in one place, and the list of who has access is auditable at any time in your identity provider.

What about the code you write, who owns it?

You do, on payment. Code, prompts, pipelines, model artifacts, infrastructure configuration, and documentation transfer as standard. We do not licence back or retain rights. Repositories live in your git organisation from day one.

Do you sign our security questionnaire?

Yes, and we can usually turn one around inside a week. This page and our engagement contract answer roughly 80% of what appears in most questionnaires; the remainder is engagement-specific and we complete it in writing.

Do you carry insurance?

Yes: professional indemnity and cyber liability appropriate to the engagement size, with certificates available under NDA. Limits and coverage are itemised in the engagement contract.

How do you handle incidents?

Named on-call from the team who built the system, defined response times in the retainer, and a written post-incident review within one week of any Sev-1 or Sev-2. Silence is not an option we offer.

Can you deploy inside our VPC or on-premise?

Yes. Our own products run on self-hosted k3s (Hetzner), and we regularly deploy inside client VPCs on AWS, GCP, and Azure. On-premise is supported where the requirement justifies the operational overhead; we will say plainly if it doesn’t.

Next step

Send us your security questionnaire.

Or bring the scoping call first. We can complete most questionnaires alongside the written scope.

Prefer async? hello@visionnexera.com · We reply within one business day.

ASKArchitect⌘K