Trust
Security & privacy
Last updated July 8, 2026
Nomosyn reads sensitive company communications to surface legal exposure, so privacy is architectural — not a policy bolted on afterward. Two ideas shape everything below: your data is analyzed by your own AI, and every organization is cryptographically isolated from every other.
Your AI, your key
You connect your own AI provider with your own API key. Your content is analyzed by the provider you choose, on your key — not routed through a Nomosyn-owned model.
Tenant isolation
Every table is protected by database row-level security, so one organization's data is never reachable from another's session.
Write-only credentials
API keys and integration tokens are stored server-side and never returned to the browser — you only ever see the provider name and the last four characters.
Attorney review
Full guidance is gated: a flagged item's detailed guidance reaches a company only after their engaged attorney has reviewed and pushed it.
Your AI, your key
Nomosyn is bring-your-own-AI. Each company connects its own AI provider using its own API key, and detection runs on that key against that company's own data. Keys are write-only: they are stored server-side, are never sent back to the browser, and are readable only by tightly-scoped database functions — the app surfaces just the provider name and the last four characters. When Nomosyn learns from usage to improve its detection rules, that analysis also runs on each company's own key over only that company's own data; no key ever accesses another company's data, and only generic, anonymized rule proposals are pooled for review.
Isolation & access
Access is enforced in the database with row-level security, not just in application code. A company's users see only their own organization's data; an attorney sees only the companies they are actively engaged to represent. Access is currently invitation-only. Agent memory is private to each user by default and is shared company- or firm-wide only when that user chooses. Key workflow actions — flags, reviews, pushes, resolutions, and messages — are recorded in an activity trail, and connected apps can be revoked instantly from the Integrations page, which also purges the data pulled from them.
Encryption
All traffic is encrypted in transit with TLS, and data is encrypted at rest (AES-256) by our database and hosting providers.
Connected apps
Nomosyn requests least-privilege, read-focused access to the tools you connect. It reads message history to detect legal signals; it does not post messages on your behalf, and it never edits or deletes your content. One necessary exception: to read a Slack channel's history, the connected bot must be a member of that channel, so it joins channels for the sole purpose of reading them. You can disconnect any integration at any time, which removes its access and the data derived from it.
Document sharing — nothing is stored
When you send a document to your legal team (or your attorney sends one to you), Nomosyn does not keep a copy. The file is delivered as an ordinary email attachment and is never written to our database or file storage — it passes through our servers in memory only, for the moment it takes to send, and is then discarded. Our email provider does not retain message content either. What we do keep is a minimal, content-free record for audit: who sent it, the filename, size, and time, and your acknowledgement of the notice shown at send time. Because attachments leave Nomosyn by email, we ask you to confirm each time that you are not sending privileged or highly sensitive material through the platform. If a document is truly sensitive, share it through your own secure channel.
Compliance (in progress)
Nomosyn is an early-stage platform. We are building toward SOC 2 and, for customers in regulated industries, HIPAA-aware handling and Business Associate Agreements. These are goals we are working toward, not certifications we hold today — we will say so plainly here as each is achieved. If your procurement process has specific requirements, reach out and we'll tell you exactly where we stand.
Sub-processors
We rely on a small set of infrastructure providers to run the platform (hosting, database, and email delivery), plus the AI provider each customer chooses and connects themselves. A current list is available on request.
Reporting a concern
If you discover a potential vulnerability, please contact security@nomosyn.com. We aim to acknowledge reports within one business day.