Trust Center

Security is not a feature. It's the foundation.

NISHRAM is built for the world's most regulated industries. On-premise AI, field-level authorization, multi-tenant isolation, and complete audit trails.

Security Architecture

Every layer of NISHRAM is designed with security-first principles.

JWT Authentication

Industry-standard JSON Web Token authentication with configurable expiration and refresh token rotation.

BCrypt Password Hashing

All passwords hashed with BCrypt. No reversible encryption, no plaintext storage.

Role-Based Access Control

Admin, Manager, Technician, and Readonly roles with configurable permissions per module.

Field-Level Authorization

Control which roles can view, edit, or export specific data fields on any entity.

Multi-Tenant Isolation

Complete data separation between tenants at the database level. No shared tables, no data leaks.

On-Premise AI

All AI models run locally on your infrastructure. No cloud API calls, no external data processing.

Complete Audit Trails

Every access, modification, and API call logged with user ID, timestamp, and change details.

Encryption Everywhere

AES-256 encryption at rest, TLS 1.3 in transit. Database backups encrypted and stored securely.

Compliance Readiness

GDPR

Compatible

Data minimization, right to deletion, consent management. On-premise deployment for EU data residency.

SOC 2 Type II

Ready

RBAC, audit trails, encrypted connections, and access logging meet SOC 2 security principles.

ISO 27001

Aligned

Information security management controls aligned with ISO 27001 framework requirements.

Data Sovereignty

Supported

Full on-premise deployment option. Your data never leaves your infrastructure or jurisdiction.

Deployment Options

Cloud (SaaS)

Managed hosting with automated updates, backups, and monitoring.

On-Premise

Full deployment on your infrastructure. Docker or native installation. AI runs locally.

Air-Gapped

Zero internet dependency. Full functionality including AI inference without any external connections.

Need a Data Processing Agreement?

We provide standard DPAs for all Enterprise customers. Custom security reviews, penetration test results, and compliance questionnaires available on request.

Contact Security Team →