Security by architecture, then by controls
The hosted service never needs your rows, so it never receives them.
The strongest control is the one that makes a leak structurally impossible. DataNivra is designed so the hosted service never needs your rows.
Design principles
- Customer-resident processing. Discovery, profiling, subsetting, masking, synthesis, validation, certification and provisioning run in your environment. The control-plane code base does not even contain the row-processing engine.
- Zero raw-production-data egress. Every field that crosses the boundary is classified as control metadata, an aggregate metric, an evidence reference or a secret reference. Messages containing anything else are rejected on both sides.
- Outbound-only connectivity. The agent initiates every connection over HTTPS. No inbound ports, no VPN peering, no database exposure.
- Secret references, not secrets. Source credentials and masking keys stay in your secret store; the control plane only ever sees names such as a vault path.
- Fail closed. Uncertain privacy or integrity state stops the job. Failed or revoked datasets are never provisioned.
- Tamper-evident audit. Privileged actions produce hash-chained audit events; certification evidence is kept customer-side with checksums.
- Tenant isolation. Every API request is scoped to a tenant; one tenant cannot enumerate or infer another.

Your data centre or cloud account is where rows are read, transformed and stored. That does not change when you use DataNivra.
Text description
- Your environment: Engine output (rows stay local) → Report builder (metadata only) → EgressGuard: schema + content checks
Connection: Allowed: metadata, aggregates, evidence & secret references — Blocked: rows, samples, credentials
- DataNivra Cloud: Ingress validation → Metadata store & audit
What we do not claim
DataNivra helps you run privacy and governance programmes — for example work related to HIPAA, GDPR or PCI DSS — by keeping production data in your environment and producing evidence. Using a tool does not make an organisation compliant, and masking alone is not proof of anonymization. We do not display certification badges we have not earned.
Report a vulnerability
Use the contact form, say that it concerns security, and do not include vulnerability details or any customer data until we reply with a private channel.
Want to check our claims yourself? See trust and verification. For what the controls do not cover, see known limitations and residual risks.