Enterprise buyers expect to see how we protect customer content before they send a file.
This page is the public summary. Reports are linked or available on request.
Attested
GDPR controls
On 18 September 2026, Nativ Technologies, Inc. completed a GDPR controls attestation.
Independent review in the Comp AI platform confirmed that we implemented controls mapped
to selected requirements of the GDPR (EU) 2016/679. Next review: 18 September 2027.
This is a controls attestation, not an ICO or EU government certificate.
For security and procurement teams
Trust Center
Policies, framework status, questionnaires, and NDA-gated documents live in our
Comp AI Trust Center at
trust.inc/nativ-technologies-inc.
SOC 2 Type II observation runs 1 July 2026 through 30 September 2026. Request access
there for the report when it is issued.
Open Trust Center →
Infrastructure
- API on Google Cloud Run; customer files in Google Cloud Storage
- Database and authentication on Supabase (production in London)
- Dashboard hosted on Vercel
- Encryption in transit (TLS 1.2+) and at rest via our cloud providers
- Secrets in Google Secret Manager, not in source control
Data protection
- Localization is user-initiated; account PII is not sent to AI providers
- We do not use customer content to train models
- AI outputs require human review before they are applied
- Production and staging are separate projects and credentials
-
Subprocessors are listed at
usenativ.com/legal/subprocessors
Application security
- Supabase Auth with MFA and optional SSO
- Role-based access control and row-level security
- API keys, rate limiting, and dependency scanning
Questions and vulnerabilities
Security, privacy, DPAs, and report requests:
founders@usenativ.com.
Vulnerability reports: we aim to respond within 48 hours.