Security & Trust

Your improvement data describes how your operation runs. Here is what we do to protect it, and where we are still building.

Compliance status

NexLean.ai does not hold a SOC 2 report yet. We are building the controls and evidence for a SOC 2 Type I assessment first, then Type II. We will list the report here, and share it under NDA, once an independent auditor has issued it. Until then, the sections below describe what is actually in place today.

Tenant isolation

Every organization's data is separated at the database layer with row-level security on all tables. A query from one organization cannot read another organization's rows, even if application code has a bug. Admin actions, such as exporting or deleting an organization, are limited to organization admins and checked on the server.

Encryption and authentication

  • Data is encrypted in transit over TLS and encrypted at rest by our database provider.
  • Passwords are stored hashed by our authentication provider. We never see or store them in plain text.
  • Sessions use secure cookies, and protected routes require a signed-in user.
  • Card payments are handled by Stripe. Card numbers never reach our servers.

How we handle AI

  • The AI Kata Coach sends only the current challenge's target condition, current condition, active obstacle, experiment history, and your message to Anthropic's Claude API. Nothing is sent unless you use the Coach.
  • We use Anthropic's commercial API, whose terms state that customer inputs and outputs are not used to train Anthropic's models.
  • Coach usage is rate limited per user to prevent abuse.

Your data, your control

  • Organization admins can export all of their organization's data at any time.
  • Users can delete their own account, and admins can delete the whole organization. Both are permanent.
  • We do not sell customer data, and we do not use it for advertising.

Subprocessors

We use these vendors to run the service. We will update this list when it changes.

VendorPurposeData involved
SupabaseDatabase, authentication, file storageAccount, organization, and challenge data
VercelApplication hostingRequest metadata; no stored customer content
AnthropicAI Kata Coach responses (Claude API)Challenge context and coach messages, only when the Coach is used
StripeSubscription billingBilling contact and payment details (card data never touches our servers)
ResendTransactional emailRecipient email address and message content
SentryError monitoringError and performance diagnostics

Report a vulnerability

If you find a security issue, email saintmba@nexlean.ai with the details. We will acknowledge it within two business days and keep you updated until it is fixed. Please give us a reasonable chance to fix an issue before disclosing it.

Security questionnaires

Reviewing us for procurement? Email us and we will complete your security questionnaire and sign a data processing agreement.

Last updated: September 2026