How Nebula Cloud protects your data, secures execution, and provides verifiable control at every layer — from multi-tenant cloud to air-gapped sovereign environments.
Security Architecture
Nebula Cloud is designed with isolation, least-privilege, and verifiability as foundational principles — not bolt-on features.
Workspaces run in isolated compute environments. No shared state between tenants. GPU memory cleared between sessions. Network segmentation enforced at infrastructure level.
Deploy the entire Nebula Cloud platform in your own cloud account (AWS/Azure/GCP VPC). Your network, your encryption keys, your data — Nebula Cloud runtime manages execution only.
Full platform on your premises with local AI models and zero cloud dependency. Policy-controlled connectivity allows you to define exactly what crosses the boundary.
Complete disconnection from internet. All models, tools, and capabilities pre-packaged. Designed for classified environments and critical national infrastructure.
You control where data resides, how long it persists, and who can access it. Configurable retention policies, geographic constraints, and automatic purge schedules.
Role-based access control (RBAC) with project, workbench, and resource-level granularity. SSO via SAML/OIDC. MFA enforcement. Session management with idle timeout.
Verification & Auditability
Complete lineage: who executed what, when, with which data, tools, and models. Immutable audit logs with tamper detection.
Every output artifact is cryptographically hashed. Verify that outputs have not been modified after generation. Execution receipts link inputs to outputs.
Replay any workflow with identical inputs and verify consistent outputs. Environment snapshots capture exact tool versions and model weights used.
Data encrypted at rest (AES-256) and in transit (TLS 1.3). Customer-managed encryption keys available for enterprise and sovereign deployments.
Compliance Posture
Architecture alignment: Nebula Cloud is designed to align with enterprise compliance frameworks including ISO 27001, SOC 2, and sector-specific regulations. The platform architecture supports the technical controls required by these frameworks.
What we do NOT currently claim: We do not currently hold SOC 2 Type II certification, ISO 27001 certification, FedRAMP authorization, or HIPAA BAA agreements. Customers requiring these certifications should discuss their compliance requirements directly with our security team.
Sovereign and air-gapped deployments inherit the compliance posture of your own infrastructure — Nebula Cloud provides the platform, you provide the certified environment.
Roadmap: Formal certification programs are planned. Contact security@nebulacloud.ai for current status and compliance documentation.
From intent to verified engineering artifact.