Security & Trust

Security and privacy at Fabraix.

We hold our own stack to the same bar we test yours against. Nyx is pure blackbox: no integration, no source, no model weights, and no access to your internal network. Pointing it at a production agent adds almost nothing to your attack surface, and it never trains on what it sees.

How we operate

Every engagement is built to keep your systems safe.

Four principles govern how Nyx runs against your agent.

Pure blackbox

Nyx needs a way to reach your agent, an endpoint, URL, or phone number, and nothing else. No credentials to internal systems, source, model weights, or VPC access.

Isolated & ephemeral

Each run executes in a sandboxed environment that is created for that engagement and torn down when it ends. Customers and targets are logically isolated.

Synthetic by design

Every payload is synthetic and every secret is a canary. Nothing real is exfiltrated from your environment, so a "successful" attack proves the risk without causing it.

Scoped with you

Testing intensity and boundaries are agreed up front. Destructive or irreversible actions are observed and reported, not executed against your real assets.

Compliance & standards

Independently audited, and building toward more.

We run a formal compliance program with continuous control monitoring. The Trust Center holds the live status, our policy pack, and the current subprocessor list.

AICPA SOC — SOC 2

SOC 2 Type II

In progress

Our SOC 2 Type II examination is underway, with controls monitored continuously in the meantime. Current status and, once available, our report are in the Trust Center under NDA.

GDPR

GDPR & data protection

Our processes are designed to protect personal data, and we can execute a Data Processing Agreement. For regulated or sensitive data, scope it with us before testing begins.

Data privacy & usage

Your data is used to run your scan, and nothing more.

We collect the minimum needed to test your agent and deliver your findings, and we are deliberate about what we keep.

Never trained on your data

Your prompts, your agent's responses, and every finding are never used to train any model, and never sold or shared.

Minimal, configurable retention

We retain scan transcripts and findings to power your dashboard and reports. Retention is configurable, and data is deleted on request and on account closure.

Purpose-limited use

Data is used only to run your engagement, produce your report, and support you. Encrypted in transit with TLS 1.2+ and at rest with AES-256.

Frequently asked

The questions security teams ask.

How do I report a security vulnerability?
Email founders@fabraix.com. We commit to prompt triage, coordinated disclosure, and crediting the researchers who help us improve. A published security.txt is planned. You can also probe our agents in the open at Playground.
How can I make a data request?
Email founders@fabraix.com and we'll action a request to access, export, or delete the data we hold for you. Data is also deleted on account closure.
Do you train on our data or share it?
No. Your prompts, your agent's responses, and every finding are never used to train any model, and never shared or sold. They are used only to run your scan and produce your report.
Do you need access to our code, models, or internal network?
No. Nyx is pure blackbox. It only needs a way to talk to the agent, an endpoint, a URL, or a phone number, plus any authentication you would give a normal user.
How is our data isolated from other customers?
Logical isolation per customer and target. Scans run in isolated, ephemeral environments created per run and destroyed afterward.
How is data encrypted, and where is it hosted?
TLS 1.2+ in transit and AES-256 at rest, using our cloud provider's managed encryption. We host on Google Cloud; the current subprocessor list lives in the Trust Center.
How do you test without causing real harm or leaking real secrets?
Payloads are synthetic and secrets are canaries. Destructive actions are observed rather than executed against real assets, and testing intensity is scoped with you up front.
Do you support SSO, audit logging, and a DPA?
Yes, SSO and audit logging are available on enterprise plans, and we can execute a Data Processing Agreement. For regulated data, scope it with us before testing.