← Home

Security and Trust

Enterprise buyers expect to see how we protect customer content before they send a file. This page is the public summary. Reports are linked or available on request.

Last updated: 18 September 2026

Attested

GDPR controls

On 18 September 2026, Nativ Technologies, Inc. completed a GDPR controls attestation. Independent review in the Comp AI platform confirmed that we implemented controls mapped to selected requirements of the GDPR (EU) 2016/679. Next review: 18 September 2027.

This is a controls attestation, not an ICO or EU government certificate.

For security and procurement teams

Trust Center

Policies, framework status, questionnaires, and NDA-gated documents live in our Comp AI Trust Center at trust.inc/nativ-technologies-inc.

SOC 2 Type II observation runs 1 July 2026 through 30 September 2026. Request access there for the report when it is issued.

Open Trust Center →

Infrastructure

  • API on Google Cloud Run; customer files in Google Cloud Storage
  • Database and authentication on Supabase (production in London)
  • Dashboard hosted on Vercel
  • Encryption in transit (TLS 1.2+) and at rest via our cloud providers
  • Secrets in Google Secret Manager, not in source control

Data protection

  • Localization is user-initiated; account PII is not sent to AI providers
  • We do not use customer content to train models
  • AI outputs require human review before they are applied
  • Production and staging are separate projects and credentials
  • Subprocessors are listed at usenativ.com/legal/subprocessors

Application security

  • Supabase Auth with MFA and optional SSO
  • Role-based access control and row-level security
  • API keys, rate limiting, and dependency scanning

Questions and vulnerabilities

Security, privacy, DPAs, and report requests: founders@usenativ.com. Vulnerability reports: we aim to respond within 48 hours.