Security & data

Security & data

Where your data lives, who can reach it, how it is protected and backed up, and how to raise a concern.

Status: draft, under review. Items marked to be confirmed are being finalised with Nia and will be replaced before this page is treated as a commitment.

Where your data lives

WhatWhereRegion
The platform database (accounts, organisations, submissions, parsed figures, report records, Advisor conversations, audit log)Neon, a managed PostgreSQL serviceLondon (United Kingdom)
Uploaded and generated files (submissions, templates, policy and knowledge documents, generated reports, profile pictures)Cloudflare R2 object storageEuropean Union jurisdiction
The application itselfVercelLondon (lhr1)
Error monitoringSentryEU data region

The full list of service providers that handle data on Nia's behalf, with what each receives, is published on the Sub-processors page.

Who can reach it

  • Invitation only. Nobody can create an account or an organisation on their own; the Nia team provisions each fund and sends the first invitation.
  • Roles. Each organisation has owners, administrators and members. Destructive actions such as deleting a template, a submission or a report are limited to owners and administrators, and that limit is enforced on the server, not only hidden in the interface.
  • Tenant isolation. Every query is scoped to the signed-in user's organisation. A fund cannot see another fund's data; this is covered by automated cross-tenant tests that run on every change.
  • Two-factor sign-in is required for platform-administrator (Nia staff) sessions; organisation administrators and users can enable it on their own accounts.
  • Support access. When the Nia team needs to look at a fund's workspace to help, the support session is recorded in the audit log with the reason, and support sessions cannot act as the user for legal acceptances.

AI and document processing

  • PDF, image and scanned files, Word files with no readable text, and any PDF or Word data submission in which the Platform's own reader finds no reportable figures, are sent to the external parsing service; spreadsheets, CSV, Policy Hub documents and Advisor attachments are always read on the platform. Nia tells every user this at sign-up.
  • AI requests are routed only to a fixed list of model hosts with zero-data-retention and no-training terms. A request that cannot be served by one of those hosts fails rather than falling back to another provider.
  • Figures that the AI reconstructed rather than read directly are flagged, and a reviewer must acknowledge the flag before the submission can be approved.

The plain-language explanation is on How the platform uses AI.

Backups and recovery

WhatHow oftenKept for
Database, continuous point-in-time recoveryContinuous, covering the last 6 hours6 hours
Database, independent full copy held away from the database providerCopies were taken on 1, 2 and 3 September 2026; the job is not running on a schedule at present (its scheduler is unavailable) and the copies are unproven until a restore drillNo retention window is promised; the provider's 6-hour point-in-time recovery window is the control for database restores
Uploaded and generated files, copied to a separate backup bucketDailyDeleted 35 days after they are taken, enforced by a storage lifecycle rule on the backup bucket

What that means in practice today: the database can be restored to any instant within the last six hours. Independent copies were taken on 1, 2 and 3 September 2026; the job that takes them is not running on a schedule at present, and no copy is relied on until a restore from it has been rehearsed. Files can be restored to the previous daily copy. Restores are performed by a named person into a fresh environment and verified before anything is switched over; nothing restores automatically over production.

What has been rehearsed: a point-in-time database restore (August 2026) and a single-file recovery from the daily copy (August 2026). A full restore from the independent database copy and a timed end-to-end cut-over have not yet been rehearsed; recovery-time targets are to be confirmed and will be published with the service-level agreement.

Retention and deletion

Advisor conversations have a 12-month retention setting; the automated purge is a planned control not yet in operation. Abandoned uploads are removed after 24 hours. Retention periods for uploaded documents, submissions and generated reports are to be confirmed and will be published in the retention schedule; until then they are kept for as long as the organisation exists. Users can delete their own account from their settings; an organisation's owner can delete the organisation from its settings, or ask the Nia team to do it.

Transport and browser protections

All traffic is over HTTPS with strict transport security. The application sends a content-security policy, frame and content-type protections, a referrer policy and a permissions policy on every response. Only strictly necessary cookies are set; there is no advertising or analytics tracking.

Raising a concern

Related pages: Privacy Policy · Terms of Service · Cookie Notice · Support

On this page