Security and deployment

Define the boundary before the first decision runs.

Deploy Nodes in Nodes Cloud, inside a single-tenant customer VPC, or on customer-managed on-premises infrastructure. The selected boundary defines where data, models, agents, workflows, traces, and telemetry may operate.

SOC 2 Type II attested · HIPAA and GDPR aligned · Named human authority · Review scope and evidence

Deployment options

Choose the operating boundary the decision requires.

Deployment flexibility is a platform capability. Security claims must follow the selected boundary, so each option is described separately.

01 · Nodes Cloud

Nodes-managed cloud deployment.

Data, model access, isolation, retention, and telemetry are defined inside a Nodes-managed operating boundary and the customer agreement.

Managed
02 · Customer VPC

Single-tenant inside the customer's cloud.

Run the platform inside an approved AWS, Azure, or GCP boundary with customer-specific weights and private data paths.

VPC-resident
03 · On-premises

Customer-managed infrastructure.

Run the platform, models, agents, workflows, and Decision Traces inside an approved on-premises environment.

Customer-managed
04 · Private boundary

Zero customer production-data egress.

Private VPC and on-premises configurations can keep customer production records and customer-specific intelligence inside the approved customer boundary. Verify all model, connector, and operational paths.

Configuration-specific
Attestation and alignment

SOC 2 Type II attested. HIPAA and GDPR aligned.

The SOC 2 Type II report is available under NDA. HIPAA and GDPR describe operational alignment, not certifications. Each deployment requires review of its configuration, customer obligations, and applicable agreements. Inspect the scope and materials.

SOC 2 Type II · attested
HIPAA · operationally aligned
GDPR · operationally aligned
Deployment compliance · customer and counsel review
Auditability

Inspect the evidence and authority behind the action.

Nodes works within configured permissions. Actions requiring approval remain gated by the customer's policy. Named people control consequential decisions and changes to production workflows; routine steps can continue within an already approved scope.

The broader platform design links evidence, model and policy versions, human questions and edits, approval state, action, and later outcome in a Decision Trace. Ask to inspect those fields in the proposed application. The current insurance evidence does not establish the full autonomous runtime or automated learning loop.

Test permission revocation, a changed plan after approval, and a partially completed action. Agent-run history should account for execution; operational telemetry must not be the only record of a business decision. Customer-designated workflows can require a second signer.

Integration controls · design for review

Test the stop condition before trusting the connector.

The connector design uses proposed field mappings, visible uncertainty, and human verification. Require a demonstration that a renamed or drifted field stops flowing instead of being guessed at. Automatic discovery and repair coverage must be established for the proposed environment.

01

Permissions and data paths

Use existing authentication and least-privilege scopes for every connected system.

02

Mapping confidence

Record why each source field maps to a canonical definition and where confidence is limited.

03

Human acceptance

Require an approval record before uncertain evidence enters a decision program.

04

Schema change

Pause the affected flow and route the change for review instead of silently remapping it.

One reference deployment

Legal approval took 17 days after six vendors were rejected on architecture.

The same Fortune 500 insurance deployment moved from contract to production in 34 days. These observed results describe one customer environment and do not promise the same timeline elsewhere.

17 days · legal approval
34 days · contract to production
Live since January 2025
SOC 2 Type II attested
Ownership and exit

Your decision history stays under your control.

The customer retains separable customer-specific intelligence defined in the agreement: source evidence, graph relationships, context models, human judgments, Decision Traces, outcomes, and applicable learned artifacts. Customer-specific weights and calibration artifacts are included where they exist and the agreement defines them.

Practical portability needs a sample export. Ask which records it contains, how identifiers and relationships survive, which schemas and provenance come with it, and what remains usable without Nodes. Agree retention, formats, transition support, and any release or escrow terms before production.

Customer ownership does not provide indefinite use of Nodes' licensed runtime. Nodes retains its platform code and pre-existing reusable intellectual property; agent operation, connector maintenance, updates, and support follow the service agreement. Confidential company memory is not pooled across tenants by default.

Security library

Inspect the architecture behind the claims.

These technical explainers remain available for security and procurement review.

Diligence

Map the data path, decision gate, and stop conditions first.

Bring one repeated decision, the systems it crosses, the outcome you measure, and the boundary that governs it.