How it worksProductTrustIntegrationsPricingCompany
Sign inJoin the beta

Your conversations,
under your control.

An agent that records what you say and show, then acts on your behalf, needs a higher bar. Nebula is built for it — local-first capture, least-privilege access, and a complete audit trail of every action.

Where we actually are

Pre-certification, and saying so.

Nebula is an early-stage company in private beta. We are not SOC 2 certified, and we don't have an ISO 27001 certificate or a HIPAA BAA to offer you. The Type II process starts as we onboard paying customers.

What design partners get instead: a written description of the controls below, our subprocessor list, a signed DPA, and direct access to the team building it. If a claim isn't on this page, we're not making it.

  • SOC 2
    Type II planned — not yet certified
  • GDPR
    Data rights & DPA supported
  • CCPA
    Access & deletion honoured
  • DPA
    Signed on request
How we protect data

Defense in depth, by default.

Every layer of Nebula is designed so that sensitive conversations stay sensitive.

Encryption in transit & at rest

TLS 1.3 in transit, AES-256 at rest. This is not end-to-end encryption — transcription runs server-side unless you choose a local model, and we say so rather than overclaiming. Enterprise can bring customer-managed keys.

Run the engine where you need it

Pin the Nebula engine to a region, or deploy it inside your own network on Enterprise so no conversation leaves your infrastructure.

SSO, SCIM & RBAC

SAML single sign-on, automated provisioning, and granular owner / admin / member / viewer roles on Enterprise.

Data residency & retention

Choose where conversations are stored, set custom retention windows, and have deletion requests honoured automatically rather than by support ticket.

Least-privilege write access

Every integration is scoped per tool and per action. Nebula gets permission to move a deal stage, not permission to your whole CRM.

Guest mode privacy

Without an account, all data — including search — stays entirely in your browser's local storage and never reaches our servers.

The audit log

Evidence for every action, not a black box.

An agent that writes to your systems has to be able to show its work. Every action Nebula takes is recorded with the evidence behind it, exportable for your compliance reviews.

  • The exact utterance that triggered it, with a timestamp
  • The verification result and confidence score
  • Who approved it, or which rule let it run automatically
  • What the target system returned, including failures
audit-entry.json
// one entry, exactly as exported
{
  "action": "crm.deal.stage.update",
  "source": {
    "utterance": "I'll bump the deal to Negotiation",
    "speaker": "maya@acme.com",
    "at": "00:14:22"
  },
  "verified": { "grounded": true, "confidence": 0.94 },
  "approval": "auto · reversible-internal",
  "result": { "status": 200, "reversible_until": "24h" }
}
Where your data goes

A clear path, with off-ramps you control.

Whatever you switched on — audio, screen, camera — is captured, transcribed and processed by the Nebula engine. You choose the region it runs in, and Enterprise can run it inside your own network so nothing leaves your infrastructure.

  • No training on your conversations — ever
  • One engine — no third-party model vendor in the path
  • Self-hosted deployment keeps everything inside your network
  1. Capture
    Only the sources you enable. Processed on-device, streamed over TLS 1.3
  2. Transcribe
    Processed in your chosen region, stored AES-256
  3. Plan & verify
    The Nebula engine, in the region you choose
  4. Store & retain
    Custom retention, audit logs, deletion on demand
Security FAQ

The questions reviewers ask.

Not yet. Nebula is pre-certification: the SOC 2 Type II process begins as we onboard paying customers. We say so plainly rather than implying a report exists. Design partners get a written description of our security posture, our subprocessor list, and direct access to the team building it.

In transit with TLS 1.3 and at rest with AES-256. This is not end-to-end encryption: transcription happens server-side unless you run a local model, so Nebula can process the audio you send. If you need data never to leave your network, Enterprise can run the engine self-hosted inside your own infrastructure.

No. Nebula runs its own model, and it is trained on data we own and license — never on customer conversations. That holds on every plan, and it is not something you have to opt out of.

Only within the autonomy level you set. By default, external and irreversible actions require explicit approval, drafts wait for review, and only reversible internal actions run automatically. Write access is scoped per tool and per action, and every action lands in the audit log with its source, confidence, approver and result.

Consent capture is visible rather than buried in settings, and we document a process for two-party-consent jurisdictions and for GDPR. Screen and camera are off unless you turn them on, and a window and app blocklist keeps password managers and unrelated windows out of the screen record.

Email security@nebula.best. Reports go straight to the engineering team and we aim to acknowledge within one business day.

Going through a security review?

Ask us for the security posture document, our subprocessor list, a signed DPA, and answers to your standard questionnaire. We'll turn them around quickly.

Security that gets
you to yes.

Bring Nebula to your security review with everything they'll ask for.