Security Overview
Last updated: 10/2026
1. Purpose
(1) Security, privacy, and responsible data stewardship are foundational principles of NebulaOne.
(2) This Security Overview provides a high-level description of the security measures, governance practices, and operational safeguards implemented to protect Customer Data, Candidate Data, organizational assessment data, and related information processed through NebulaOne's Services.
(3) This document is intended to provide transparency regarding NebulaOne's security posture and does not disclose sensitive architectural or operational security details.
2. Security Principles
NebulaOne's security program is guided by the following principles:
- (a) Security by Design
- (b) Privacy by Design
- (c) Least Privilege Access
- (d) Defense in Depth
- (e) Customer Data Isolation
- (f) Human Oversight
- (g) Responsible AI Governance
- (h) Continuous Improvement
- (i) Risk-Based Security Management
3. Infrastructure Security
(1) NebulaOne uses professionally managed cloud infrastructure providers to operate and deliver its Services.
(2) Infrastructure security measures may include:
- (a) infrastructure monitoring;
- (b) system hardening;
- (c) network segmentation;
- (d) backup procedures;
- (e) availability monitoring;
- (f) disaster recovery planning;
- (g) operational resilience controls.
(3) Infrastructure configurations are reviewed periodically to support security, reliability, availability, and resilience.
3.1 Data Hosting and Residency
(1) NebulaOne uses Amazon Web Services ("AWS") as its primary cloud infrastructure provider.
(2) Customer Data and Candidate Data are hosted on infrastructure operated by AWS in Frankfurt am Main, Germany.
(3) NebulaOne seeks to process and store information in locations appropriate to applicable legal, contractual, operational, and regulatory requirements.
(4) Where personal data is transferred across jurisdictions, NebulaOne implements appropriate safeguards as described in its Privacy Policy and Data Processing Addendum.
4. Data Protection
(1) NebulaOne maintains technical and organizational safeguards designed to protect information against unauthorized access, disclosure, alteration, loss, or destruction.
(2) Such safeguards may include:
- (a) encryption in transit;
- (b) encryption at rest;
- (c) secure key management;
- (d) controlled access mechanisms;
- (e) secure storage practices;
- (f) authentication controls.
(3) Data protection measures are periodically reviewed and updated based on evolving risks and operational requirements.
5. Access Controls
(1) Access to systems and information is granted based on business need and the principle of least privilege.
(2) Access control measures may include:
- (a) role-based access controls;
- (b) account lifecycle management;
- (c) authentication requirements;
- (d) access reviews;
- (e) privilege management procedures.
(3) Personnel are granted access only to the information reasonably necessary to perform their responsibilities.
6. Application Security
(1) Security considerations are incorporated throughout the software development lifecycle.
(2) Application security practices may include:
- (a) secure development practices;
- (b) code reviews;
- (c) dependency management;
- (d) vulnerability remediation;
- (e) testing and quality assurance processes.
(3) Security issues identified during development are prioritized according to their assessed risk and impact.
7. AI Security and Governance
(1) NebulaOne applies governance controls to AI-assisted workflows and systems.
(2) AI-related safeguards may include:
- (a) human oversight requirements;
- (b) access restrictions;
- (c) output review mechanisms;
- (d) monitoring and evaluation procedures;
- (e) responsible use controls;
- (f) governance and accountability measures.
(3) AI-generated outputs are intended to support human decision-making and are not autonomous decisions.
(4) Customers must not rely solely on AI-generated outputs when making employment, hiring, compensation, promotion, disciplinary, restructuring, workforce planning, or termination decisions.
(5) Human reviewers remain responsible for evaluating relevant facts, evidence, business context, and legal obligations before acting on AI-assisted recommendations.
7.1 Third-Party AI Providers
(1) NebulaOne may utilize third-party AI service providers to support certain features and functionality of the Services.
(2) Such providers may include:
- (a) OpenAI;
- (b) other AI infrastructure providers selected by NebulaOne from time to time.
(3) NebulaOne evaluates AI providers based on:
- (a) security;
- (b) privacy protections;
- (c) contractual commitments;
- (d) reliability;
- (e) operational suitability.
(4) Customer confidential information is not used by NebulaOne to train public foundation models.
(5) Information sharing with AI providers is governed by applicable contractual, technical, organizational, and legal safeguards.
8. Customer Data Isolation
(1) Customer trust is fundamental to NebulaOne.
(2) Customer information remains logically separated from information belonging to other customers.
(3) Information provided by one Customer is never used to generate outputs, recommendations, diagnostics, assessments, reports, or organizational insights for another Customer.
(4) NebulaOne does not operate cross-customer learning systems using Customer confidential information.
(5) NebulaOne does not use Customer confidential information, Candidate Data, organizational assessment data, interview content, voice recordings, or video recordings to train public foundation models.
9. Incident Management
(1) NebulaOne maintains processes designed to identify, investigate, manage, and respond to security incidents.
(2) Security incidents may be assessed according to:
- (a) severity;
- (b) scope;
- (c) potential impact;
- (d) legal obligations;
- (e) operational risk.
(3) Where required by applicable law or contractual obligations, affected Customers will be notified of confirmed incidents without undue delay.
10. Vendor Management
(1) NebulaOne may engage trusted third-party service providers to support the delivery of the Services.
(2) Such providers may include:
- (a) cloud infrastructure providers;
- (b) communication providers;
- (c) analytics providers;
- (d) AI providers;
- (e) security service providers.
(3) Vendors are evaluated based on security, privacy, reliability, and operational requirements.
(4) NebulaOne maintains oversight processes intended to monitor critical vendor relationships.
11. Business Continuity
(1) NebulaOne maintains processes designed to support operational continuity and resilience.
(2) Such processes may include:
- (a) backup procedures;
- (b) recovery procedures;
- (c) redundancy measures;
- (d) operational monitoring;
- (e) resilience planning.
(3) Business continuity measures are periodically reviewed and may evolve over time.
12. Shared Responsibility Model
(1) Security is a shared responsibility.
(2) NebulaOne is responsible for securing the Services, infrastructure, and systems under its control.
(3) Customers remain responsible for:
- (a) managing user access;
- (b) protecting credentials;
- (c) configuring permissions appropriately;
- (d) complying with legal obligations;
- (e) reviewing outputs before acting on them;
- (f) ensuring lawful use of the Services.
13. Future Security Commitments
(1) NebulaOne is committed to continuously strengthening its security and compliance posture.
(2) As the Services evolve, NebulaOne may pursue additional certifications, audits, assessments, compliance frameworks, and security initiatives appropriate to customer requirements and industry expectations.
(3) Security controls, governance processes, and operational safeguards may be updated to address evolving threats, technologies, and regulatory requirements.
13.1 Security Reporting
(1) Individuals who identify a potential security vulnerability affecting NebulaOne are encouraged to report it responsibly.
(2) Security reports may be submitted to:
(3) NebulaOne will make reasonable efforts to review and investigate reported vulnerabilities.