Security and deployment

Define the boundary before the first decision runs.

Deploy Nodes in Nodes Cloud, inside a single-tenant customer VPC, or on customer-managed on-premises infrastructure. The selected boundary defines where data, models, agents, workflows, traces, and telemetry may operate.

SOC 2 Type I and Type II held · Named human authority · Signed Decision Traces · Deployment terms defined per customer

Deployment options

Choose the operating boundary the decision requires.

Deployment flexibility is a platform capability. Security claims must follow the selected boundary, so each option is described separately.

01 · Nodes Cloud

Nodes-managed cloud deployment.

Data, model access, isolation, retention, and telemetry are defined inside a Nodes-managed operating boundary and the customer agreement.

Managed
02 · Customer VPC

Single-tenant inside the customer's cloud.

Run the platform inside an approved AWS, Azure, or GCP boundary with customer-specific weights and private data paths.

VPC-resident
03 · On-premises

Customer-managed infrastructure.

Run the platform, models, agents, workflows, and Decision Traces inside an approved on-premises environment.

Customer-managed
04 · Private boundary

Zero customer production-data egress.

Private VPC and on-premises configurations can keep customer production records and customer-specific intelligence inside the approved customer boundary.

Policy enforced
Attestations

SOC 2 Type I and Type II are what Nodes holds.

Reports cover the Nodes control environment and are available under NDA. Customer regulatory requirements and domain-specific reviews are scoped per deployment. Architecture alone does not create legal compliance.

SOC 2 Type II · held
SOC 2 Type I · held
Customer control review · scoped per deployment
Domain-specific legal review · scoped per deployment
Auditability

Every recommendation carries its evidence into execution.

A signed Decision Trace records the evidence available, model and policy versions, recommendation, human questions and edits, approval state, action, and later outcome.

Customer-designated workflows can require a second signer. Security, model-risk, legal, internal-audit, and business teams inspect the same record.

Integration controls

A renamed or drifted field stops flowing instead of being guessed at.

Templated connectors match discovered fields to a customer-approved glossary with confidence bands. A human verifies uncertain mappings before use.

01

Permissions and data paths

Use existing authentication and least-privilege scopes for every connected system.

02

Mapping confidence

Record why each source field maps to a canonical definition and where confidence is limited.

03

Human acceptance

Require an approval record before uncertain evidence enters a decision program.

04

Schema change

Pause the affected flow and route the change for review instead of silently remapping it.

One reference deployment

Legal approval took 17 days after six vendors were rejected on architecture.

The same Fortune 500 insurance deployment moved from contract to production in 34 days. These observed results describe one customer environment and do not promise the same timeline elsewhere.

17 days · legal approval
34 days · contract to production
Live since January 2025
SOC 2 Type I and Type II held
Ownership and exit

Your decision history stays under your control.

The customer retains the assets defined in the agreement, including customer data, customer-specific learned weights, Decision Blueprints, Decision Traces, outcome history, and calibration artifacts.

Export formats, transition periods, escrow, and release triggers are defined contractually. The Nodes software license, agent operation, connector maintenance, monitoring, updates, support, and continuous recalibration end with the service.

Security library

Inspect the architecture behind the claims.

These technical explainers remain available for security and procurement review.

Diligence

Map the data path, decision gate, and stop conditions first.

Bring one repeated decision, the systems it crosses, the outcome you measure, and the boundary that governs it.