Trust center

Security and trust center

What protects your documents, what we keep, who else handles data, and what has been audited.

Verify a receipt

About 3 minutes on a sample file. Your email and name open it. We never ask for your ACE login or bank details.

Modes

What protects your documents in each mode?

What changesSealedPrivate by default. Provable on request.StandardMay use outside AI. Staff access logged.
Runs inAMD SEV-SNP confidential virtual machines (NexQloud Sealed)NexQloud cloud. Outside AI may be used.
EncryptedIn your browser before upload, at rest, and in memory while the run is liveIn transit and at rest

Where your data is processed, in both modes: our FAQ.

What Standard protects

An outside AI provider may process your documents, only on terms that bar training. Nothing trains on them. Only named NexQloud staff can open them, to fix an exception or answer a support request, and every access is logged.

Each security claim, and how to check it
ClaimBacked byHow you checkLimits
In Sealed mode, no outside AI provider receives your documentsOur architecture and the subprocessor listRead the subprocessor list. In Sealed mode, the receipt lists everything that could leaveIn Standard mode, an outside AI provider may process them, only on terms that bar training
Your documents are never used to train any modelOur terms; in Sealed, the measured codeThe DPA clause; the receipt's Model lineIn Standard mode, it rests on our terms and our controls, and on the AI provider's terms
In Sealed mode, no one sees your documents without your consentThe four conditions on the Sealed pageVerify any receiptThe ten limits on the Sealed page
Every Standard-mode staff access is loggedThe access logAsk for your account's access logThe log is ours; an audit tests it

Retention

What do we keep, and for how long?

Sealed erases the working copy when the run ends. Standard keeps documents for the engagement, then deletes them on schedule.

Every retention period, by mode
DataSealedStandard
Your uploaded documentsReadable only inside the sealed machine during the run, then cryptographically erasedKept for the engagement, then deleted on schedule
Extracted fields, matches and working filesErased with the working copyKept for the engagement, then deleted with the documents
Exceptions and your answersSeen only by you and your brokerKept for the engagement
Claim package, CSV and evidence trailSent to your broker and you, encrypted to them. No readable copy kept by usSent to your broker and you
Claim totals and billing recordsKept with our billing recordsSame
ReceiptsKept. Download yours any timeNot issued in Standard
Account detailsLife of the account, then deleted on scheduleSame
Staff access logsNo staff access to logKept on schedule
System logs, with no document contentKept on scheduleSame
BackupsNo backups of document contentDocuments stay in backups for a set time after deletion
Outside AI provider (Standard only)Not used in SealedPer the provider's terms
Consents (broker sharing; adviser status view)⁠[1]Kept on scheduleSame

The records CBP requires are yours and your broker's to keep: claim records for three years after the claim liquidates.⁠[2] We are not your record keeper, so keep your own copies.

If a court orders us to keep data

We can keep only what we hold. In Sealed mode, that does not include your documents.

Subprocessors

Who else handles data for us?

Sealed uses no AI model provider. Standard may use one, only on terms that bar training.

Each kind of subprocessor, by mode
SubprocessorWhat it does for usData it receivesMode
Sealed hosting providerHosts for sealed machinesEncrypted data. AMD hardware keeps the host from reading a sealed machine's memory (limits apply)Sealed
Cloud hosting providerHosting for StandardDocuments and outputs, encrypted at restStandard
Email providerAccount and notice emailsNames, email addresses, notice text. No documentsBoth
Error monitoring providerError reportsError data with no document contentBoth
Support toolSupport ticketsWhat you write to usBoth
Billing providerInvoicesClaim totals and billing contactsBoth
AI model providerAI model for StandardDocuments, only on terms that bar trainingStandard
  • We give notice before adding a subprocessor that receives your data.
  • Your broker is not our subprocessor. You engage it directly, and it answers to you and to CBP.
  • An adviser or refund firm that referred you sees your claim status only with your consent.

Audits

What has been audited, and what has not?

ItemStatus
SOC 2 Type 2The report is available under NDA on request.
Vulnerability disclosure policy and security.txtPublished
AMD bulletins we trackListed on the verify page

What we do not hold

We do not hold CMMC, FedRAMP, or ITAR or EAR authorizations for this service, and Sealed is not one.⁠[3]

Certifications held by NexQloud's other services or by our hosting providers do not transfer to NexQloud Drawback. Our hosting providers' own reports are theirs, not ours.

Disclosure

How do you report a security problem?

Our vulnerability disclosure policy covers how to report, scope, safe harbor and timelines.

  • We confirm receipt and keep you updated until the issue is closed.
  • We credit you on our thanks page if you wish.
  • Safe harbor: we will not pursue good-faith research that follows the policy.
Our security.txt file

Our security.txt file lists the same contacts in the standard format (RFC 9116).⁠[4]

security.txt

Get started

Prove it on every claim.

Run the demo in Sealed mode. About three minutes.

  1. 01

    Choose Sealed.

    Pick Sealed mode when you upload your records.

    WhoYou

  2. 02

    The agent works inside the enclave.

    Your records are read inside AMD SEV-SNP hardware.

    WhoThe agent

  3. 03

    You get a signed receipt.

    The working copy is erased. Anyone you share the receipt with can verify it.

    WhoYou

Your email and name open the demo. We never ask for your ACE login or bank details.

Book a discovery call
Ready now? Start a claim

Incidents

What happens if something goes wrong?

  1. Contain.

  2. Tell you and your broker.

    If we confirm an incident that affects your data, we notify you and your broker.

  3. Say what we know.

    What happened and when; what data; which accounts; which importer numbers may be affected; what we have done; who to call.

  4. Keep you updated.

    Until the incident is closed.

  5. Write it up.

    A written report after it closes.

What an incident can reach in Sealed mode

A breach of our servers can reach only what we hold: account details, claim totals, receipts, logs, and encrypted data we cannot open.

A flaw in a sealed release could affect its runs, so we log every release, revoke a bad one and tell you (how revocation works).

Vendor reviews

Need this for a vendor review?

Tell us through our contact page. We reply within 2 business days.

Ten questions

Our answers to the ten questions

Ten questions to ask any AI vendor, from Why Sealed.

1Does any outside AI model provider receive my documents?

Sealed

No. An open-weight model runs inside the sealed machine.

Standard

One may, only on terms that bar training. It is on our subprocessor list.

2Is my data used to train any model?

Sealed

Never. The model's weights hash is also published.

Standard

Never. The clause is in our data processing agreement (/legal/dpa/, section 2).

3How long are copies kept?

Sealed

The working copy is cryptographically erased when the run ends. The signed receipt is kept.⁠[7]

Standard

For the engagement, then deleted on schedule (retention).

4Who can read my documents?

Sealed

Only the people you approve, such as your broker. Exceptions go to you or your broker.

Standard

Named NexQloud staff, only for exception review and support. Every access is logged.

5Can you prove it?

Sealed

Yes. Check any run's receipt against AMD's keys at /sealed/verify/. Read the limits first.

Standard

Through our controls: your account's access log, our terms, and the dated audits.

6What if your terms change?

We give notice before any change, and changes are never retroactive.

Sealed

The same, and a change can't reach a working copy that no longer exists.

Standard

The same.

7Which other vendors touch my documents?

Only those on the subprocessor list. We give notice before we add one.

Sealed

The same list. No outside AI provider, analytics tool or support desk receives your documents.

Standard

The same, plus the AI provider's own vendors.

8What can the agent reach and send?

Your workspace, your broker's queue and claim totals for billing. It has no tools that send data elsewhere.

Sealed

The same, and the receipt names the exact code that ran.

Standard

The same.

9Who decides what is filed with CBP?

Sealed

A licensed customs broker, ours or yours, reviews every line and files.

Standard

The same.

10Do you ever ask for my ACE login or bank details?

Sealed

No, never.

Standard

No, never.

Demo

Run the demo

Watch the agent turn a sample file into a claim folder. About 3 minutes.

We'll email you the link and add you to the waitlist. Unsubscribe anytime. We never ask for your ACE login or bank details.