Enterprise-grade security

Your files are safe with us

We handle sensitive business files every day — invoices, leases, bank statements, tax forms. Security isn't a feature, it's the foundation everything else is built on.

AES-256encryption at rest
TLS 1.2+encryption in transit
Zero trainingon your files
1-click deleteGDPR forget

Compliance

Built on certified infrastructure, designed for regulated industries.

SOC 2-Eligible Infrastructure

Neruva runs on Google Cloud Platform, which maintains SOC 1/2/3, ISO 27001, and ISO 27017 certifications. Our infrastructure inherits these controls.

GDPR Compliant

Full data subject rights: export, forget, delete. One-click data erasure from the dashboard. We process data lawfully under legitimate interest and contractual necessity.

PIPEDA Compliant

As a Canadian company, we comply with the Personal Information Protection and Electronic Documents Act. Your data is handled according to Canadian privacy law.

Technical protections

Multiple layers of security protect your data at every stage.

Encryption in Transit

All data transmitted between your browser and our servers is encrypted using TLS 1.2+ (HTTPS). No exceptions, no fallback to unencrypted connections.

Encryption at Rest

All stored data is encrypted at rest using AES-256, Google Cloud's default encryption standard. Encryption keys are managed by Google Cloud KMS.

Account Isolation

Every account is a fully isolated namespace. No code path allows one account to access another's files or extracted data. This is our strictest architectural invariant.

Authentication

Firebase Authentication with Google OAuth 2.0 or email/password. Sessions are managed with secure tokens. Multi-factor authentication (TOTP) available for all accounts.

Access Controls

Role-based access within your account. Admin controls for user management, API key rotation, and billing. All actions are logged in the audit trail.

Secure File Handling

Uploaded files are stored in Google Cloud Storage with signed URLs that expire after 7 days. Files are isolated per account with path-level access controls.

How we handle your data

Transparency about what happens to your files.

Your Data, Your Control

You own your files and all extracted data. We never claim ownership of your content. Export everything as CSV, JSON, or delete it permanently — anytime.

No AI Training

Your files are never used to train AI models. Not ours, not anyone else's. Files are processed for extraction only, then the extracted data is stored in your secure account.

Data Retention

Extracted data is retained until you delete it. Original files are stored for preview access with configurable retention. On account deletion, all data is permanently erased within 30 days.

GDPR Right to be Forgotten

One-click data erasure from Settings. This permanently destroys all your files, extracted data, and knowledge graph entries. Irreversible by design.

Infrastructure

Google Cloud Platform

All services run on GCP (us-central1). Google Cloud maintains SOC 1/2/3, ISO 27001, ISO 27017, ISO 27018, and PCI DSS certifications.

Firebase Services

Authentication, database, and file storage powered by Firebase — Google's enterprise application platform with built-in security controls and automatic scaling.

Payment Security

Payments processed by PayPal. We never see or store your credit card number. PayPal is PCI DSS Level 1 certified.

Security FAQ

Can Neruva employees see my documents?

No. Your data is encrypted and isolated in your own namespace. We do not have a workflow or tool that allows browsing customer documents. Access would require explicit engineering action with audit logging.

What happens if there's a data breach?

We will notify affected customers within 72 hours, as required by GDPR and PIPEDA. We will provide details of what was affected and what steps we're taking. We maintain incident response procedures and conduct regular security reviews.

Where is my data stored?

All data is stored in Google Cloud Platform's us-central1 region (Iowa, USA). Data is encrypted at rest with AES-256 and in transit with TLS 1.2+.

Do you train AI on my documents?

No. Never. Your documents are processed for extraction only. We use proprietary AI models that do not train on customer data.

Can I delete all my data?

Yes. One click in Settings > Security > Delete all data. This permanently erases all documents, extracted data, and knowledge graph entries. It cannot be undone.

Do you have SOC 2 certification?

We run on SOC 2-certified infrastructure (Google Cloud Platform). We are working toward our own SOC 2 Type II audit as we scale. Contact us at info@neruva.io for our current security documentation.

Questions about security?

We take security seriously. If you have questions, need a security review, or want to report a vulnerability, contact us.

info@neruva.io