Security and privacy at Fabraix.
We hold our own stack to the same bar we test yours against. Nyx is pure blackbox: no integration, no source, no model weights, and no access to your internal network. Pointing it at a production agent adds almost nothing to your attack surface, and it never trains on what it sees.
Every engagement is built to keep your systems safe.
Four principles govern how Nyx runs against your agent.
Pure blackbox
Nyx needs a way to reach your agent, an endpoint, URL, or phone number, and nothing else. No credentials to internal systems, source, model weights, or VPC access.
Isolated & ephemeral
Each run executes in a sandboxed environment that is created for that engagement and torn down when it ends. Customers and targets are logically isolated.
Synthetic by design
Every payload is synthetic and every secret is a canary. Nothing real is exfiltrated from your environment, so a "successful" attack proves the risk without causing it.
Scoped with you
Testing intensity and boundaries are agreed up front. Destructive or irreversible actions are observed and reported, not executed against your real assets.
Independently audited, and building toward more.
We run a formal compliance program with continuous control monitoring. The Trust Center holds the live status, our policy pack, and the current subprocessor list.
SOC 2 Type II
In progressOur SOC 2 Type II examination is underway, with controls monitored continuously in the meantime. Current status and, once available, our report are in the Trust Center under NDA.
GDPR & data protection
Our processes are designed to protect personal data, and we can execute a Data Processing Agreement. For regulated or sensitive data, scope it with us before testing begins.
Your data is used to run your scan, and nothing more.
We collect the minimum needed to test your agent and deliver your findings, and we are deliberate about what we keep.
Never trained on your data
Your prompts, your agent's responses, and every finding are never used to train any model, and never sold or shared.
Minimal, configurable retention
We retain scan transcripts and findings to power your dashboard and reports. Retention is configurable, and data is deleted on request and on account closure.
Purpose-limited use
Data is used only to run your engagement, produce your report, and support you. Encrypted in transit with TLS 1.2+ and at rest with AES-256.
The questions security teams ask.
How do I report a security vulnerability?
security.txt is planned. You can also probe our agents in the open at Playground.