Control at every layer of the request path.

Nirmos is designed to keep credentials protected, access scoped, and production traffic observable from application entry to provider execution.

Security built into the operating path.

Controls matter most where data and credentials move. Nirmos applies them around authentication, authorization, execution, and operational review.

CONTROL / 01

Credential protection

Provider credentials are encrypted before persistence and decrypted only when a gateway request needs them. Secret values are kept out of client-facing credential data.

CONTROL / 02

Scoped access

Organization scope and permission checks protect gateway and control-plane operations. API credentials are accepted through headers, not URL query parameters.

CONTROL / 03

Request safeguards

The gateway applies payload limits, input guards, timeouts, rate limits, security headers, and replay-protection controls around authenticated traffic.

CONTROL / 04

Operational visibility

Request IDs, trace context, response timing, and credential activity records help teams investigate behavior without placing secrets in logs.

Data handling

Keep sensitive paths narrow and explicit.

Nirmos separates configuration from execution, uses environment and organization boundaries, and limits credential use to the provider request path.

01Receive
02Authorize
03Execute
04Observe

Shared responsibility

Secure AI infrastructure depends on platform controls and disciplined customer configuration working together.

01Nirmos

Protect platform boundaries, credential paths, access checks, and gateway controls.

02Your team

Scope keys, manage membership, review access, and configure retention for your requirements.

03Together

Use least privilege, rotate credentials, separate environments, and investigate unexpected traffic.

This page describes current engineering practices, not a certification or guarantee. We do not claim SOC 2, ISO 27001, HIPAA, or other compliance status here.

Found a potential security issue? Tell us privately.

Send a clear description, affected surface, and reproduction details. Avoid including live secrets or customer data in the initial report.