Security by architecture, then by controls

The hosted service never needs your rows, so it never receives them.

The strongest control is the one that makes a leak structurally impossible. DataNivra is designed so the hosted service never needs your rows.

The agent connects out; nothing connects inInside your network the DataNivra agent reads sources read-only and resolves credentials from your own secret store. It opens outbound HTTPS connections to DataNivra Cloud, which receives secret references, never values. There are no inbound connections into your network.Your networkSecret storekeys and credentialsSourcesread-onlyDataNivra agentfails closedoutbound HTTPS onlyDataNivra Cloudreferences onlyno inbound connections

Design principles

  • Customer-resident processing. Discovery, profiling, subsetting, masking, synthesis, validation, certification and provisioning run in your environment. The control-plane code base does not even contain the row-processing engine.
  • Zero raw-production-data egress. Every field that crosses the boundary is classified as control metadata, an aggregate metric, an evidence reference or a secret reference. Messages containing anything else are rejected on both sides.
  • Outbound-only connectivity. The agent initiates every connection over HTTPS. No inbound ports, no VPN peering, no database exposure.
  • Secret references, not secrets. Source credentials and masking keys stay in your secret store; the control plane only ever sees names such as a vault path.
  • Fail closed. Uncertain privacy or integrity state stops the job. Failed or revoked datasets are never provisioned.
  • Tamper-evident audit. Privileged actions produce hash-chained audit events; certification evidence is kept customer-side with checksums.
  • Tenant isolation. Every API request is scoped to a tenant; one tenant cannot enumerate or infer another.

Your data centre or cloud account is where rows are read, transformed and stored. That does not change when you use DataNivra.

How raw data is kept from leavingInside your environment, engine output stays local; a report builder produces metadata; the EgressGuard checks every outbound message against allow-listed schemas and content detectors. Allowed out: control metadata, aggregate metrics, evidence references and secret references. Blocked: rows, samples and credentials. In the cloud, ingress validation rejects anything non-conforming before it is stored.Your environmentEngine output (rowsstay local)Report builder(metadata only)EgressGuard: schema +content checksDataNivra CloudIngress validationMetadata store & auditAllowed: metadata, aggregates, evidence & secret referencesBlocked: rows, samples, credentials
How raw data is kept from leaving. Inside your environment, engine output stays local; a report builder produces metadata; the EgressGuard checks every outbound message against allow-listed schemas and content detectors. Allowed out: control metadata, aggregate metrics, evidence references and secret references. Blocked: rows, samples and credentials. In the cloud, ingress validation rejects anything non-conforming before it is stored.
Text description
  1. Your environment: Engine output (rows stay local) → Report builder (metadata only) → EgressGuard: schema + content checks

    Connection: Allowed: metadata, aggregates, evidence & secret references — Blocked: rows, samples, credentials

  2. DataNivra Cloud: Ingress validation → Metadata store & audit

What we do not claim

DataNivra helps you run privacy and governance programmes — for example work related to HIPAA, GDPR or PCI DSS — by keeping production data in your environment and producing evidence. Using a tool does not make an organisation compliant, and masking alone is not proof of anonymization. We do not display certification badges we have not earned.

Report a vulnerability

Use the contact form, say that it concerns security, and do not include vulnerability details or any customer data until we reply with a private channel.

Want to check our claims yourself? See trust and verification. For what the controls do not cover, see known limitations and residual risks.