NuralNestAI

Security

Security at NuralNest

Last updated: July 24, 2026

A Nest is one private space for everything a household, a friend group, or a team of professionals shares โ€” receipts, policies, records, the documents you'd keep in a fireproof box. This document describes how that information is protected at every layer, who can access it, the third parties involved, and how to report a vulnerability.

The short version: your data is encrypted in transit and at rest, isolated to your own Nest at the storage layer, never used to train AI models, and never sold or shared for advertising or analytics. Our team cannot read your documents or chats.

System overview

Every request follows the same path: encrypted from your device, your identity verified, and your Nest opened only after that check passes.

How your request travels

Every step is encrypted, and nothing is opened until we've confirmed it's really you.

๐Ÿ“ฑ Your devices

๐Ÿ“ฑPhone & tabletthe NuralNest app
๐Ÿ’ปComputerthe web app
โœ‰๏ธForwarded emailsend documents straight in
โ†“Encrypted connection ยท identity verified on every request

๐Ÿ”’ Secure entry

๐Ÿ”Sign-in you controlpasskeys, Face ID, or a code
โœ…Every request checkedconfirmed against your account
โ†“

โš™๏ธ NuralNest services

๐Ÿ“ฅTakes in your documentsreads, organizes, understands
๐Ÿ’ฌAnswers your questionsthe assistant + your books
๐Ÿ””Watches dates & renewalsso you don't have to
These services keep only what they need โ€” never your original file names.
โ†“

๐Ÿชบ Your group's private Nest

๐Ÿ—‚๏ธIsolated storageyour Nest's documents, on their own
๐Ÿ”‘Encrypted at restwith dedicated keys in production
๐Ÿง Your private indexthe assistant searches only your Nest
๐Ÿ“Š Service health We watch operational logs to keep the service running โ€” these never contain the contents of your documents.

Where your data lives

All NuralNest data is stored on cloud infrastructure located in the United States. We do not replicate or back up your data outside the US.

Each group gets its own dedicated storage area:

Storage areas are named with a random per-group identifier, never your email or name. There is no shared "everything" store โ€” by design, code paths that read across groups do not exist.

Encryption

In transit

At rest

Tenant isolation

Multi-tenant systems most often leak by accident โ€” a query forgets its filter, a path resolves the wrong way. NuralNest is built so the easy path is the safe path:

Defense in depth

Each layer is enforced independently โ€” a failure in one does not remove the checks in the next.

Defense in depth

Six independent layers stand between a request and your data.

๐Ÿ“ก Transport

๐Ÿ”’TLS-encrypted connectionon every request and response
โ†“

๐Ÿชช Identity

๐ŸŽซSigned token checkedverified on every single request, not just at sign-in
โ†“

โš™๏ธ Application

๐Ÿ›‚Least-privilege accessscoped to the signed-in identity, for that one request only
โ†“

๐Ÿชบ Per-group isolation

๐Ÿ—‚๏ธSeparate storageeach Nest's documents on their own
๐ŸงญSeparate search indexeach Nest's index, never shared
๐ŸงพRedundant group filtera second, independent check on every lookup
โ†“

๐Ÿ”‘ Encryption at rest

๐Ÿ”Envelope encryptionper-group keys
๐ŸšซStaff cannot decryptconfigured this way in production
โ†“

๐Ÿงพ Audit

๐Ÿ“œKey actions recordedan append-only audit trail

Access controls

Authentication

Subprocessors

NuralNest is built on a small set of carefully chosen vendors. Each is bound by a written agreement that restricts use of your data to providing service to us, and none may use it for their own purposes. We do not sell or rent your data to any of them. This is the full list of third parties involved in any feature.

VendorFeature it powers · what we sendRegion
Amazon Web Services Hosting, storage, authentication, AI processing, and security infrastructure โ€” the platform NuralNest runs on. Your data stays within AWS. United States
Apple Optional Sign in with Apple, and App Store in-app purchases on iPhone. Apple verifies your identity or processes the payment; we receive a confirmation, never your card number. United States
Google Optional Sign in with Google, and Google Play in-app purchases on Android. As with Apple, we receive a confirmation, never your card number. United States
Stripe Card payments for subscriptions purchased on the web. Stripe processes your card details directly; we never see or store your full card number. United States
Tavily Assistant web search, when you ask about current events or something outside your Nest. We send your search query only. United States
WeatherAPI.com Weather answers in chat. We send an approximate location only. United States
Shopping deals (SmartBuy) Finding prices & deals when you shop โ€” Scrapingdog, UPCitemDB, eBay, Commission Junction, Awin, and eBay Partner Network. We send the product you're searching for and click referrals for affiliate credit. US / global
Travel deals (SmartTrip) Finding flights & hotels when you search travel โ€” Travelpayouts. We send your trip search and click referrals for affiliate credit. Global

In every case we send only what that feature needs โ€” a search term, a location, a click, or the details required to complete a purchase. Your documents and their contents are never sent to any third party. The shopping and travel providers are reached only when you actively use those features.

As the service grows we may add subprocessors for features like calendar and email integration. Any addition will be reflected here in advance.

HIPAA

NuralNest is on the path to becoming HIPAA-eligible. The technical safeguards the HIPAA Security Rule calls for โ€” encryption in transit and at rest, per-group isolation, least-privilege access, and audit logging โ€” are already in place, and a Business Associate Agreement with our cloud provider is signed.

We are completing the remaining administrative steps before NuralNest can act as a Business Associate of a covered entity. Until we publish a HIPAA-readiness statement here, NuralNest is intended for personal and group use. If you are a healthcare provider, payer, or clearinghouse, please do not upload PHI until that statement is published.

What we never do

Your data, your control

Vulnerability reporting

If you believe you've found a security issue, we want to hear from you. Email security@nuralnest.com with a description of the issue and its potential impact, steps to reproduce if possible, and how to reach you.

We'll acknowledge receipt within two business days and keep you informed as we investigate. We don't currently run a paid bug-bounty program, but with your permission we publicly credit researchers who report valid issues. Please give us a reasonable window to fix an issue before any public disclosure, and avoid accessing data that isn't yours โ€” we won't pursue legal action against good-faith research conducted under this policy.

Incident notification

If we ever experience a security incident involving your personal information, we will notify affected users without undue delay and within the timelines required by law. The notice will describe what happened, what information was involved, what we've done, and what you can do.

Where we are today

NuralNest is in private beta. Everything described on this page is built and tested today, and each control is re-verified in our production environment before it holds any customer's documents. We publish this before launch rather than after because it is easier to hold us to it that way.

Updates to this page

Security practices evolve. Material changes to encryption, subprocessors, or access controls will be reflected here, and the "Last updated" date at the top will move forward. For broader changes to how we handle personal information, see the Privacy Policy.

Contact

Security questions or reports: security@nuralnest.com
Privacy questions or requests: privacy@nuralnest.com

United Dream Homes LLC
2300 Olympia Dr. #271761
Flower Mound, TX 75027, USA