Skip to content
Nulis Nulis AI Writing Partner
Security & Compliance Document 04 / Section 2.1

SOC 2 Type II since November 2022. GDPR-aligned since the day we shipped.

Nulis is the AI writing platform that publishes its security posture as plainly as its marketing. What follows is the filing a procurement lead needs to clear review — the certifications, the controls, and the documents you can request today.

No customer draft has ever trained a shared model. No tenant has ever shared storage with another. Every claim below is backed by a dated artifact.

SOC 2 Type II GDPR ISO-aligned EU–US DPF 99.4% originality
§1   Data handling

Your drafts stay in your tenant. They do not train our models.

Every piece of content a customer writes in Nulis is stored encrypted at rest (AES‑256) inside a logically isolated tenant on cloud infrastructure operated by AWS (us‑east‑1, eu‑west‑1, and ap‑southeast‑2, selectable per workspace). Drafts, brand‑voice samples, and style guides are scoped to that tenant by default and are never copied into a shared training corpus, a regression dataset, or a third‑party fine‑tune pipeline.

What leaves your browser

When you ask Nulis to draft, the request is routed to the inference layer with a workspace‑scoped token. The prompt — your prompt, in your voice — is processed for the single purpose of returning the requested output, then retained only inside your tenant and only for as long as your workspace retention policy dictates. Workspace admins can set retention to 7, 30, or 90 days, or disable retained inference logs entirely.

What never leaves Nulis

  • No training on customer content. The brand‑voice models you train inside your workspace are stored as vectors in your tenant only. They are not aggregated into a shared embedding, a public model card, or a customer‑wide checkpoint.
  • No cross‑tenant access. Workspace data is partitioned by a per‑tenant key prefix and a per‑request authorization token. No engineer, account manager, or support agent has standing access to customer drafts; access is granted only through a time‑boxed, ticket‑linked elevation that is itself logged and reviewed.
  • No silent third‑party transfer. Nulis does not resell, syndicate, or relay customer content to advertising networks, data brokers, or model resellers. Our sub‑processor list (below) is the complete list, reviewed quarterly.

Encryption, in two lines

In transit: TLS 1.3 with forward secrecy on every client and inter‑service connection. At rest: AES‑256 with envelope encryption; per‑workspace data keys wrapped by AWS KMS keys that rotate annually and on any suspected compromise. Backups are encrypted with a distinct key class and stored in a separate AWS account with no human access path.

The remainder of this page is a line‑by‑line reference for the security questionnaire your team will send us. Each control maps to an artifact you can request under NDA.

§2   Operational controls

Four guarantees, each small enough to verify on a single call.

We organise Nulis's security architecture into four operational control areas. Procurement teams have cleared these by scheduling a 45‑minute walkthrough with our security lead — the calendar link is in the next section.

  1. 01

    Access control

    SSO via SAML 2.0 and OIDC is available on every paid workspace, with SCIM 2.0 provisioning on Business and Enterprise tiers. Role‑based permissions separate authors, reviewers, and admins; workspace owners can enforce hardware‑key MFA and IP allow‑lists. Privileged access to production is gated by short‑lived credentials issued through a hardware‑backed bastion, with every session recorded for review.

  2. 02

    Encryption

    All customer data is encrypted at rest with AES‑256 and in transit with TLS 1.3. Per‑workspace data encryption keys are wrapped by KMS keys that rotate annually; backup keys are isolated to a separate account. Nulis does not store customer payment data — billing runs through Stripe, which maintains its own PCI DSS Level 1 attestation.

  3. 03

    Vendor management

    Nulis operates on a tightly bounded sub‑processor set: AWS for hosting, Stripe for billing, Zendesk for support tickets, and Datadog for internal observability. Each sub‑processor carries a current SOC 2 Type II report on file, reviewed annually by our security lead. The complete list, with data flows and regions, is published at /security/ and updated within 30 days of any change.

  4. 04

    Incident response

    A documented incident response plan is tested twice a year via tabletop exercise and once a year via a controlled red‑team engagement with an independent third party. Customer‑impacting incidents trigger notification within 72 hours of confirmation, per our published SLA, with a designated security contact listed in every enterprise contract.

§3   Audit evidence

The documents a security reviewer will ask for, in the order they will ask for them.

Send this list to your procurement team. Each row is an artifact that already exists, with a date and a request path. We turn around requests inside two business days under NDA.

SOC 2 Type II report
Issued by an independent AICPA‑registered firm. Observation window 1 November 2023 – 31 October 2024; renewed annually since November 2022. Request via [email protected] · NDA on file
GDPR Data Processing Addendum
Counter‑signable DPA available on request, incorporating the European Commission's 2021 Standard Contractual Clauses and the UK International Data Transfer Addendum. Auto‑countersigned on Enterprise contracts · available to Business tier under NDA
Content originality audit
Independent evaluation across 12,400 first‑draft outputs: 99.4% pass Copyscape and Originality.ai standard thresholds on first generation, without human rewriting. Audit conducted Q3 2024 by a third‑party research firm
Penetration test summary
Annual external pen test by a CREST‑accredited firm; the executive summary and remediation status are available to prospects under NDA. Most recent test closed November 2024 with zero high‑severity findings outstanding. Next scheduled test: November 2025
EU–US Data Privacy Framework
Nulis, Inc. is registered with the U.S. Department of Commerce's EU–US Data Privacy Framework, the UK Extension, and the Swiss–US Data Privacy Framework. Listing active since July 2023 · annual self‑certification
Sub‑processor list & data‑flow diagram
The current sub‑processor inventory, with the regions each sub‑processor operates in and the categories of data they handle, is published and updated within 30 days of any change. Always available · no NDA required

If your security questionnaire covers a control not addressed above — FedRAMP boundary, customer‑managed keys, residency pinning — write to [email protected]. A human will reply the same business day.

Next step

Clear procurement, then take the editor for a 14‑day drive.

When your security review closes, the next step is a workspace where the controls above are visible end‑to‑end — audit log, SSO, retention, the whole surface. Start a 14‑day trial on the Business tier. No credit card, no sales call required to evaluate.

8,200+ content teams onboarded since 2021 · SOC 2 Type II since November 2022 · HQ at 68 Jay Street, Brooklyn, NY.