Your network data is sensitive. We treat it that way.
Your geodatabase is the system of record behind critical infrastructure. This page is for the people who have to sign off on letting anyone near it — how your data moves, where it lives, and what our AI agents are allowed to do.
Encrypted in transit
Everything moving between you, our platform, and the agent workflows travels over modern TLS — your data never crosses the wire in the clear.
Encrypted at rest, isolated per engagement
Your geodatabases and everything derived from them are encrypted at rest and isolated per engagement, with least-privilege access that is logged end to end.
Governed AI workflows
Every agent runs inside a scoped, monitored workflow — permissioned actions, engineer sign-off on changes, and a full activity trail. We never train on your data.
We work from a copy
Migration work runs against a copy of your geodatabase, so your system of record keeps running untouched while we build. Cutover happens on your schedule, with your sign-off.
US cloud hosting
Your data is processed and stored on US-region cloud infrastructure for the duration of the engagement.
Your data, your terms
We keep engagement data only as long as the engagement needs it, and we delete it on request — it's your network, not our asset.
Security is a precondition, not a phase
None of what follows is a feature we shipped once. They are the rules the work runs under, and they are the reason an assessment can start with a copy of a geodatabase and nothing else.
- 01
Least access that still does the job
We ask for a copy, not a connection. No VPN into your network, no service account in your enterprise geodatabase, no standing access to anything you run. If a task does not need a permission, it does not get one.
- 02
Nothing happens without a name against it
Every action an engineer or an agent takes is attributable. Not "the system changed it" — a person, a time, and what changed. That is what makes an answer possible months later when someone asks why.
- 03
Assume the review is coming
We build as though your security team, your auditor and an intervenor will all read the record eventually, because in this industry they do. Designing for that up front is cheaper than reconstructing it afterwards.
- 04
Your data is a liability we borrow
Holding your network data is a risk we take on, not an asset we accumulate. We keep it for as long as the engagement needs it and delete it when you say so — the safest copy is the one that no longer exists.
What an agent is allowed to touch
The agents are the part most security reviews want to understand, and reasonably so. They are not a chat window pointed at your data. Each one runs inside a scoped workflow with a defined input, a defined output and an engineer accountable for the result.
- Read the copy of your geodatabase we were given, and nothing else
- Propose mappings and transformations that an engineer reviews before anything is accepted
- Run validation passes and record every finding with the count behind it
- Reach your production systems — there is no route from an agent to your network
- Move data outside the engagement, or into a general-purpose model for training
- Commit a change to a deliverable without an engineer signing off on it
Evidence, kept as you go
An audit trail assembled after the fact is a reconstruction. The workspace records these while the work happens, and you can read them at any point.
- Membership and role changes — who was given access, by whom, and when it was taken away
- Agreement history — the comment thread, every version, and who agreed to what, with a SHA-256 hash of the signed text so a later change to it is detectable
- Validation results per migration run, and how each failure was triaged and resolved
We inherit the controls of the platforms we build on
Your data is processed and stored on major US-region cloud platforms that maintain independent, third-party security audits and publish current attestation reports. Those are their certifications, not ours, and we will not present them as ours — but they are a real part of the answer to where your data sits and who has been audited against what. We will share the current reports with your security team under NDA.
We will name every sub-processor that touches engagement data, and your network data does not move outside them.
We would rather be checkable than certified-sounding
We do not hold a formal security certification today, and we are not going to imply one with a badge in a footer. What we will do is answer your questionnaire in specifics, work under your NDA and your data-processing terms, and let your security team test the claims on this page against what we actually do. If something here does not hold up, we would like to hear about it before your auditor does.
Built to pass your review, not route around it.
We expect a security review before any data changes hands, and we're set up for it. We work under your NDA, sign your data-processing terms, and complete your security questionnaire — and the readiness assessment is designed so that conversation starts small: a copy of a geodatabase, no system access, no disruption.
Have your security or procurement team write us directly at hello@nutility.io — a real engineer answers, usually within a business day.