Your private cloud
Runs inside your AWS, Oracle or Google VPC. Data stays in your account; we never see it.
- Customer-owned account
- Private networking
- Your KMS keys
Newron is designed for buyers whose procurement, risk and audit teams ask hard questions. We deploy inside your perimeter, encrypt everything, and leave a trail for every action.
Aligned to ISO 27001 and our SOC 2 programme, and validated in regulated deployments.
The more sensitive the workload, the more isolated we deploy.
Runs inside your AWS, Oracle or Google VPC. Data stays in your account; we never see it.
Deploys into your own data centre for full physical control over data and compute.
Operates with no internet connectivity for the most sensitive government and financial workloads.
Information security management system aligned to the standard.
Type II programme covering security, availability and confidentiality (in progress).
Indian data-residency commitments; training on India-hosted data.
Security is part of how we build, not a layer on top. Our practices include code review on every change, dependency and vulnerability scanning in CI, isolated environments for development and production, and regular internal review of access and configuration. Production changes are logged and reversible.
For our own corporate operations (such as hosting our website and email) we use a small set of vetted providers under contract. For customer deployments, Newron runs inside your environment, so there are typically no Newron subprocessors in the data path. A current subprocessor list is available on request and as part of our security pack.
We welcome reports from security researchers. If you believe you've found a vulnerability, please disclose it responsibly: email our security contact with details and steps to reproduce, give us reasonable time to investigate and remediate before any public disclosure, and avoid accessing or modifying data that isn't yours. We will acknowledge your report, keep you updated, and credit you if you wish once the issue is resolved. Please do not run automated scans against customer deployments.
Yes. Under NDA we share our security documentation, including controls, architecture and subprocessor details. Request it via the contact form.
In a standard deployment, no. The system runs inside your environment and we hold no copy of your data. Support access, where granted, is scoped, just-in-time and logged.
Not without an explicit, contracted agreement. Customer data is processed under your instructions and is not used to train shared models.
We scan continuously, patch on a risk-based schedule, and operate a responsible-disclosure process for external reports.
We've answered a lot of them. Share your security and procurement requirements and we'll work through them with your team.