Trust centre

Where it runs, whose models see your code, and what is kept.

Everything on this page is public. The security pack, and anything specific to your environment, is shared after a mutual NDA.

How data moves

Shared deployment shown. Dedicated and self-hosted keep every step inside your boundary.
  1. 01 · Your side

    Your repository

    Connected branches and pushes only.
  2. 02 · EmberNest

    Scan, scope and gate

    Rules, quotes, approvals and the evidence record.
  3. 03 · Model route

    The route you chose

    Managed AI, your provider account, or local models.
  4. 04 · Back to you

    Merged change

    Through your release process, with its evidence attached.

Deployment options

SharedManaged by us
DedicatedIsolated, your own domain
Your AzureInside your tenancy
Self-hostedYour infrastructure

Whose models see the code

Managed AIRouted by EmberNest to listed sub-processors
Your accountClaude, OpenAI, Azure or OpenRouter
Local modelsNothing leaves your infrastructure

What is recorded, and for how long

RecordedApprovals, changes, tests, re-scans
Professional90 days
Business1 year
EnterpriseTo your policy

Works with how you already govern

Your controls, mapped.

Nothing here replaces a control you run. Each one gets a record behind it.

The control you runHow EmberNest supports it
Engineering standardsYour rules, held with your code, checked on every change EmberNest handles
Change controlWork is scoped, priced and approved before it starts. Changes to scope or price go back for approval
Segregation of dutiesThe person who prices the work is not the person who authorises it, and no one can close work by hand: its test has to pass
Release managementDeployments follow your release process and any approvals you require
Show all 8 controlsShow fewer
Assurance and auditEach change is linked to its approval, its test results and a fresh scan
Data sovereigntyRun in our cloud, your Azure subscription or your own infrastructure, with your own model routes
Budget controlAI usage, subscriptions and capacity are tracked against approved work, with budgets, alerts and routing policies
Existing estatesWorks on existing Java, Go, TypeScript, Python, C# and Rust codebases, not only new ones
After NDA

The security pack

Architecture, access controls, incident response and single sign-on detail, for your security review.

Request the pack