Trust, by architecture, not by badge.
Nyx is a new company and holds no certifications yet. Trust here is structural: the data is processed on your device, the design is published, and every claim below is verifiable.
Patent-pending core
The core anonymization engine is covered by a pending patent; the official prior-art search report confirmed novelty and inventive step for all claims.
Verifiable by design
Intent analysis and anonymization run on-device, prompts are not sent to a third-party classifier, so we can't see your data. Read the architecture rather than take our word. See how it works →
Encryption
Data is encrypted in transit (TLS) and at rest (AES-256), with keys managed independently. Policies and control commands distributed to the fleet are Ed25519-signed and verified before they are applied.
Tamper-evident audit
Every enforcement decision is recorded in a cryptographically hash-chained audit trail, so any in-place change is detectable by re-verification, evidence packs for the EU AI Act, GDPR, NIS2, ISO 27001, SOC 2, HIPAA and PCI-DSS.
Sovereign deployment
Nyx runs cloud-hosted, on-premise, or fully air-gapped. In sovereign and air-gapped deployments no telemetry leaves your enclave; policy updates arrive via signed, offline channels.
Critical-infrastructure heritage
Engineered by practitioners with a decade of OT and critical-infrastructure security experience (IEC 62443). The fail-closed, signed-policy posture comes from that world.
Certification roadmap
We hold no certifications today. ISO/IEC 42001 (AI management) and SOC 2 programs are in progress, target 2027. Until then, trust is architectural and the audit records are yours to verify.
Vulnerability disclosure
If you believe you've found a security vulnerability, please report it to contact@nyxai.io. We appreciate coordinated disclosure and will work with you on a timely fix.