Newron
HOME/Legal / Security
Security

Built to pass the security review.

Newron is designed for buyers whose procurement, risk and audit teams ask hard questions. We deploy inside your perimeter, encrypt everything, and leave a trail for every action.

Request our security packReport a vulnerability
01
Posture

The controls your risk team expects.

Aligned to ISO 27001 and our SOC 2 programme, and validated in regulated deployments.

01
Data stays in your environment
Newron runs in your VPC, on-premise or air-gapped. Customer data is never sent to third-party model APIs, and we hold no copy of it.
02
Encryption everywhere
TLS for data in transit and strong encryption at rest, with keys managed by you through your own KMS where you choose.
03
Least-privilege access
Role-based access control, scoped service credentials and just-in-time access for support, all logged.
04
Complete audit trail
Every model output and user action is timestamped, sourced and exportable for audit and regulator review.
02
Deployment models

You choose where it runs.

The more sensitive the workload, the more isolated we deploy.

VPC
01

Your private cloud

Runs inside your AWS, Oracle or Google VPC. Data stays in your account; we never see it.

  • Customer-owned account
  • Private networking
  • Your KMS keys
On-prem
02

On-premise

Deploys into your own data centre for full physical control over data and compute.

  • No external egress
  • Hardware you control
  • Local key management
Air-gapped
03

Fully air-gapped

Operates with no internet connectivity for the most sensitive government and financial workloads.

  • Zero outbound
  • Offline model updates
  • Sovereign by default
03
Certifications & programme

Independently checked.

Certified
ISO 27001

Information security management system aligned to the standard.

Certified
SOC 2

Type II programme covering security, availability and confidentiality (in progress).

Certified
Data residency

Indian data-residency commitments; training on India-hosted data.

Engineering practices

Security is part of how we build, not a layer on top. Our practices include code review on every change, dependency and vulnerability scanning in CI, isolated environments for development and production, and regular internal review of access and configuration. Production changes are logged and reversible.

Subprocessors

For our own corporate operations (such as hosting our website and email) we use a small set of vetted providers under contract. For customer deployments, Newron runs inside your environment, so there are typically no Newron subprocessors in the data path. A current subprocessor list is available on request and as part of our security pack.

Responsible disclosure

We welcome reports from security researchers. If you believe you've found a vulnerability, please disclose it responsibly: email our security contact with details and steps to reproduce, give us reasonable time to investigate and remediate before any public disclosure, and avoid accessing or modifying data that isn't yours. We will acknowledge your report, keep you updated, and credit you if you wish once the issue is resolved. Please do not run automated scans against customer deployments.

04
Questions

Common questions.

Can we get your SOC 2 report and security pack?+

Yes. Under NDA we share our security documentation, including controls, architecture and subprocessor details. Request it via the contact form.

Does Newron ever see our data?+

In a standard deployment, no. The system runs inside your environment and we hold no copy of your data. Support access, where granted, is scoped, just-in-time and logged.

Do you use our data to train models?+

Not without an explicit, contracted agreement. Customer data is processed under your instructions and is not used to train shared models.

How do you handle vulnerabilities?+

We scan continuously, patch on a risk-based schedule, and operate a responsible-disclosure process for external reports.

Security

Send us your questionnaire.

We've answered a lot of them. Share your security and procurement requirements and we'll work through them with your team.

Request security pack Privacy Policy