Skip to content

Public statement

Security

How naulon is built, where your data sits, and the controls that protect it. Every claim on this page is one you can verify for yourself.

Last updated July 2026
Data residency
Frankfurt, DE
Backups
Tokyo, JP · 30d
Funds held
0
Content to AI
Inference only

Where your data lives

#

The application, the database, the identity provider and the API gateway all run on a single host in Frankfurt, Germany. Encrypted nightly database backups are the one thing that leaves the EU: they are encrypted on the host and then written to object storage in Tokyo, under a 30-day lifecycle. Both locations are named on the subprocessor page, and the transfer is stated rather than buried. naulon itself is operated from Japan, which the European Commission recognises as providing an adequate level of data protection, so an EU customer's data reaching us needs no additional transfer safeguard.

One platform, many publishers, no shared reads

#

Every publisher is a separate tenant. Data is partitioned by organization and site, and every read resolves its scope from your authenticated session, never from an identifier the browser supplies. Row-level security is on for every application table; most are reachable only by the server, which re-derives your scope on each request. We treat a cross-tenant read as a vulnerability rather than a bug, and test for it adversarially.

We never hold your money

#

This is a security property, not just a business model. A buyer pays your wallet directly at the moment of a read. There is no pooled balance, no float, and no naulon-controlled account holding your earnings, so there is nothing for us to lose, freeze or misappropriate. The operator fee is a separate buyer-to-operator payment inside the same quote, never a deduction from your cut.

Where your article text goes

#

Two things are true here and they are not the same thing. Nothing about a person is sent to an outside model: not your readers, not their identities, not your account data. Your article text is sent. To build the public catalog, to make your work findable by what is inside it, and to answer a buyer's question through the hosted reading agent, extracted article text goes to Google for inference, to produce that one result and never to train a model. Google is listed on the subprocessor page. Every site carries a switch: turn off full-text discovery and that site's text stops being sent, and the stored index is removed. A tolled article still has to be paid for either way, because sending text for inference is not a free read.

Access control you operate yourself

#

Enforce MFA across your whole organization. Restrict the portal to your own network ranges. Bind your identity provider over SCIM so joiners and leavers are handled by your directory instead of by hand. Grant narrow roles from a permission engine that denies by default. List your active sessions and revoke any of them. Programmatic keys are scoped, revocable, stored only as hashes, and shown once.

Encryption, keys and secrets

#

All external traffic is TLS-terminated and plaintext HTTP is redirected. Database and object storage are encrypted at rest, and backups are encrypted before they leave the host. Runtime secrets live as encrypted parameters in a managed store and are never committed to source. Where you delegate spending authority to a hosted agent, its signing key is held only as an envelope sealed under a key-encryption key that lives outside the database, stamped with the id of the key that sealed it so keys can rotate without a mass re-encryption.

Everything privileged is on the record

#

Every change to your account is recorded with who did it, what they touched, and when. The trail cannot be edited: the database credential can insert and expire rows but holds no update permission, so history is append-only. You can export it as CSV or PDF whenever you like. Support access is part of that record. Nobody at naulon can quietly read or change your account: privileged actions need a second operator's approval, and any session where we view your account appears in your own activity log as a visible entry.

When something goes wrong

#

We operate a written incident-response runbook: severity bands based on what is at stake, the containment measures available across our infrastructure, and how we determine whether an event is a personal data breach rather than an outage. It is exercised and revised against what the exercise finds. If your data is affected you hear from us within 24 hours of us becoming aware, with what we know at that point and a named person to reply to. You are the controller, so notifying a regulator or the people affected remains your decision; our part is getting you what you need in time to make it.

Independent assurance

naulon has not completed a SOC 2 examination and does not claim one. What we maintain is a full control mapping against the AICPA Trust Services Criteria, with a verification procedure for every control, so your security team can test what we say rather than take it on trust. Customers can download it from the dashboard, and we will walk your reviewers through it or complete your questionnaire on request. Independent examination is on our roadmap.

Reporting a vulnerability

Email us and a human answers. Tell us what you found and how to reproduce it. We will not pursue you for testing in good faith against your own account and your own data. Please do not test against another customer's tenant, and please give us a reasonable chance to fix an issue before publishing it.

[email protected]

This English version is the governing text. Translations are provided for convenience only; if they differ, the English controls.