TRUST & SECURITY CENTER

Always-on, built for secure reliability.

We designed Nairo so critical workflows never stop. The platform is engineered to deliver reliable AI-powered operations with privacy, information security and regulatory compliance embedded at its core.
Security, privacy and accountability by default.
From infrastructure to AI workflows, Nairo applies operational safeguards designed to support secure collaboration in high-trust professional environments.
Encryption & secure transport
Customer data is encrypted in transit using TLS 1.2+ and protected at rest using AES-256 encryption standards.
GDPR & privacy rights
Nairo supports GDPR principles, including access, portability, correction and deletion requests for personal data.
No public model training
Customer data is not used by Nairo to train shared public AI models.
Identity & access management
Authentication, session management and workspace-level permissions help control access to sensitive information.
Infrastructure & hosting security
Nairo is hosted on Google Cloud infrastructure with encrypted storage, network security controls and environment-level isolation.
Monitoring & operational security
Infrastructure monitoring and platform safeguards help support reliable and secure platform operations.
Responsible AI operations
Nairo is designed to support professionals operating in high-trust environments where accountability, transparency and human oversight matter.
Human Oversight
AI-generated outputs should be reviewed by qualified professionals before operational, underwriting or regulatory use.
Retrieval & grounding
Nairo is designed to ground AI responses in customer-provided documents, workflows and operational context whenever possible.
AI provider governance
Selected third-party AI providers may be used depending on the workflow, with platform-level safeguards and provider agreements governing data handling.
Human accountability
Customers remain responsible for reviewing, validating and approving decisions made using AI-assisted workflows.
Documentation & Policies
Additional information regarding Nairo’s security practices, AI governance, legal terms and operational policies.
common questions
We’re here to answer your questions.
We make insurance professionals smarter by connecting three dimensions of knowledge, your organization's expertise,  market intelligence, and regulatory requirements, so that every decision you make is informed, grounded, and defensible.
1. What encryption standards do you use?
Chevron down icon
Customer data is encrypted in transit using TLS 1.2+ and protected at rest using AES-256-GCM  encryption standards, or better. Encryption is applied across storage and data transmission layers to help protect sensitive operational information.
2. Is customer data used to train AI models?
Chevron down icon
No. Customer data processed through Nairo is not used by Nairo to train shared public AI models. Where third-party AI providers are used, Nairo relies on enterprise provider agreements and platform-level controls governing data handling and retention.
3. Where is customer data hosted?
Chevron down icon
Nairo is hosted on Google Cloud infrastructure, with primary environments and storage located within the European Union. Certain AI workflows may involve selected third-party AI providers depending on the customer configuration and use case.
4. Who can access customer data?
Chevron down icon
Nairo applies authentication, session management and workspace-level access controls designed to restrict access to sensitive documents, workflows and operational data. Access permissions are managed at the workspace and organizational level.
5. Does Nairo support GDPR requirements?
Chevron down icon
Nairo is designed to support GDPR principles, including rights related to access, correction, portability and deletion of personal data. Customers may contact our team regarding privacy-related requests and data processing inquiries.
6. Are AI-generated outputs reviewed by humans?
Chevron down icon
Yes. Nairo is designed to support human-in-the-loop workflows where qualified professionals remain responsible for reviewing, validating and approving outputs generated through AI-assisted operations.
7. Which AI providers does Nairo integrate?
Chevron down icon
Depending on the workflow and customer configuration, Nairo may integrate selected third-party AI providers including OpenAI, Anthropic and Google. AI provider usage is governed through platform controls and provider agreements.
8. Are customer environments isolated?
Chevron down icon
Nairo is designed to logically separate customer environments, operational data and workflows across organizations. Environment-level controls are applied to support secure and isolated operations.
9. How does Nairo support operational security?
Chevron down icon
Nairo applies infrastructure monitoring, operational safeguards and environment separation controls designed to support reliable and secure platform operations.
10. Do you support customer-managed encryption keys (BYOK)?
Chevron down icon
Nairo is evaluating support for customer-managed encryption keys (BYOK) for enterprise environments with advanced security and compliance requirements. Our long-term infrastructure roadmap includes additional controls around key management, environment isolation and customer-specific security configurations.
11. Do you support dedicated or isolated environments?
Chevron down icon
Nairo is designed with environment-level isolation controls and is exploring additional deployment and infrastructure options for organizations with enhanced operational and regulatory requirements.
12. Can Nairo support region-specific data residency requirements?
Chevron down icon
Nairo’s infrastructure is primarily hosted within the European Union, and we continue evaluating additional deployment and regional configuration options for enterprise customers with specific data residency requirements.
13. How does Nairo approach enterprise security requirements?
Chevron down icon
Nairo’s infrastructure roadmap includes continued investment in access controls, monitoring, encryption, deployment flexibility and operational safeguards designed for high-trust professional environments.
14. Can customers request additional security documentation?
Chevron down icon
Yes. Customers may contact Nairo regarding security documentation, privacy requests, subprocessors and data processing related inquiries. Find all the relevant emails just below.
Got a question? Looking for a tailored demo? Fill out the form and we’ll be in touch shortly, usually within one business day.
We never share your data with third parties.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.