Trust Center
Trust Center
Everything a security review needs to know about Nullgen AI Blocker, written for the IT and security teams who run those reviews.
Nullgen blocks AI where the traffic starts. The browser extension classifies prompt fields on the device, and the phone app answers lookups for known AI destinations on the phone. Nothing anyone types, browses, or looks up is sent to Nullgen. What we do run in the cloud is small and described here: administrator accounts, organization policy, device records, and the plumbing that keeps them in sync. It is zero trust in the most literal sense: Nullgen never needs to be trusted with what people type or browse, because it never receives it.
Security controls
The controls we operate today, grouped by domain, and our SOC 2 alignment work.
Security controlsArchitecture and data flow
What each component sends, what never leaves the device, what we store, and where it runs.
Architecture and data flowData handling and privacy
Retention and deletion, student and child data, where Nullgen stands on FERPA, COPPA, and GDPR, and our service providers.
Data handling and privacyDeployment for IT
What installs through your device-management tool, what end users see, and which hosts to allow.
Deployment for ITVulnerability disclosure
How to report a security issue, what to expect, and the safe harbour for good-faith research.
Vulnerability disclosure
Where we stand
Controls in place, work in progress, and what is planned
The status of line items below are kept up to date on a weekly basis.
- On-device AI detection; no prompt text or browsing data collectedIn place
- Encryption in transit and at restIn place
- Multi-factor authentication on all staff accountsIn place
- Code review before changes reach productionIn place
- Infrastructure defined and deployed as codeIn place
- Point-in-time database recoveryIn place
- Documented incident response processIn place
- Vulnerability disclosure policy and security.txtIn place
- Aligning controls with the SOC 2 Trust Services CriteriaIn progress
- SOC 2 Type I auditPlanned
- Compliant with FERPA and COPPA requirementsCompliant
- Aligning with GDPR requirementsIn progress
- Third-party privacy certification (COPPA Safe Harbor, student-privacy seal)Planned
- Third-party penetration test, as part of the SOC 2 auditPlanned
We do not hold a SOC 2 report today.
Nullgen is not certified under any of these programs today.
Reviewing Nullgen for your organization?
Send us your questionnaire or ask anything these pages do not answer. Our founder answers security questionnaires directly.
Security questions and vulnerability reports
security@nullgen.aiProcurement, questionnaires, and contracts
sales@nullgen.ai
The Privacy Policy and Terms of Service are the binding documents. These pages explain how the product works so a security review can move faster.