Security and permissions

Company memory needs trust by default.

Direct answer

Nura only works with approved connected sources and is designed to respect workspace access, administrator controls, and source-level permissions already configured in your tools. Every answer is designed to remain traceable to its source.

Core controls

Core controls available in early access.

Last updated: July 2026.

01

Data access

Nura only reads from sources an administrator has explicitly connected. No source is added automatically.

02

Permission-aware retrieval

Retrieval is designed to respect the access controls already configured in each connected tool.

03

Admin controls

Workspace administrators control which sources are connected and who can query Nura.

04

Connector management

Each connector can be reviewed, disconnected, or removed by an administrator.

05

Token security

Access tokens used to connect approved sources are encrypted at rest.

06

Tenant isolation

Workspace data and company memory remain isolated between customer organizations.

Additional controls

Deletion, model usage, and provenance.

01

Data deletion

Administrators can revoke a connector and request deletion of the synchronized data associated with it.

02

Model usage

Nura does not use Customer Data to train models shared across Nura customers. Any third-party processing must follow Nura's applicable provider and customer data terms.

03

Answer provenance

Every answer is designed to include its source, date, and reasoning, providing a lightweight record of what was retrieved.

Current status

Clear about what is live and what is planned.

Nura is an early-access product. Where a control is planned rather than fully available, we state that directly instead of presenting future work as already complete.

Live now
  • Admin-controlled connectors
  • Tenant-isolated workspace data
  • Encrypted connector tokens
  • Source-backed answers
Roadmap
  • Formal security certifications
  • Expanded exportable audit trails
  • Additional compliance documentation
FAQs

Security
questions.

Common questions about permissions, data isolation, model usage, connector access, and certifications.

01Does Nura respect our existing permissions?

Yes. Nura is designed to retrieve only what a given user could already access in the connected source, based on workspace access and administrator controls.

02Can we revoke a connector Nura uses?

Yes. Administrators can disconnect or revoke a connector from workspace settings, which stops future synchronization from that source.

03Does Nura use our data to train models?

Nura does not use Customer Data to train models shared across Nura customers. Any third-party processing must follow Nura's applicable provider and customer data terms.

04Is Nura data tenant-isolated?

Yes. Workspace data and company memory are isolated per organization and are not accessible across customer workspaces.

05Does Nura have SOC 2 or similar certification?

Nura is currently in early access. Formal certifications are planned rather than complete today. Contact the Nura team for current architecture and compliance status.

Security

Review Nura's current controls
with our team.

Trace the answer back to the approved source.