Credential protection
Provider credentials are encrypted before persistence and decrypted only when a gateway request needs them. Secret values are kept out of client-facing credential data.
Security
Nirmos is designed to keep credentials protected, access scoped, and production traffic observable from application entry to provider execution.
Platform safeguards
Controls matter most where data and credentials move. Nirmos applies them around authentication, authorization, execution, and operational review.
Provider credentials are encrypted before persistence and decrypted only when a gateway request needs them. Secret values are kept out of client-facing credential data.
Organization scope and permission checks protect gateway and control-plane operations. API credentials are accepted through headers, not URL query parameters.
The gateway applies payload limits, input guards, timeouts, rate limits, security headers, and replay-protection controls around authenticated traffic.
Request IDs, trace context, response timing, and credential activity records help teams investigate behavior without placing secrets in logs.
Data handling
Nirmos separates configuration from execution, uses environment and organization boundaries, and limits credential use to the provider request path.
Secure AI infrastructure depends on platform controls and disciplined customer configuration working together.
Protect platform boundaries, credential paths, access checks, and gateway controls.
Scope keys, manage membership, review access, and configure retention for your requirements.
Use least privilege, rotate credentials, separate environments, and investigate unexpected traffic.
This page describes current engineering practices, not a certification or guarantee. We do not claim SOC 2, ISO 27001, HIPAA, or other compliance status here.
Responsible reporting
Send a clear description, affected surface, and reproduction details. Avoid including live secrets or customer data in the initial report.