Your data stays yours
We do not sell it, mine it, or train models on it. On a self-hosted deployment the database is yours outright and we never hold your production data at all.
One system holding your customers, your money and your people is only worth having if the boundaries are real. Here is exactly where ours are, including the parts that are still under way.
What we commit to
We do not sell it, mine it, or train models on it. On a self-hosted deployment the database is yours outright and we never hold your production data at all.
Every customer gets their own isolated data, not a shared table with a filter bolted on. Self-hosted customers run their own project and choose its region themselves.
TLS 1.3 between your browser and us, AES-256 for anything stored. Applied automatically, with nothing to configure.
Isolation is enforced by the database itself, not by the screen in front of it. A request that should return nothing returns nothing, whatever the interface asks for.
Who changed what, and when. Access to production systems is logged, and record history stays with the record.
Pick the provider per department, or bring your own key. The AI is not a fixed black box you have to accept along with the rest.
It drafts, suggests and prepares. Anything that changes a record, sends a message or moves money waits for a person to approve it.
Export your data whenever you want, without asking us and without a retention call. Leaving should cost you nothing but the decision.
How it is enforced
These are not aspirations. Each one is a commitment in our Data Processing Agreement, which is a contract rather than a marketing page.
Where your data lives
Self-hosted. You own the database and choose its region. We never hold your production data, and you can revoke our access at any time.
Managed. We run it for you on our infrastructure, and the region is set by the deployment rather than picked from a menu. If you need your data in a specific jurisdiction, self-hosted is the honest answer and we will say so.
Every company that touches data on our behalf is named in the sub-processor list, with its purpose and region. We keep one list rather than a friendlier summary alongside it.
Tell us and we will act on it. Report a vulnerability to security@nearsync.ai. We will not take legal action against anyone reporting a genuine issue in good faith.