NakodaX

Security

Built by people who assumed they’d be a target

We hold the permissions. We don’t hold your work. Here’s exactly what that means.

Sealed documents, data and code sitting outside a permission lattice.

What we can and can’t see

Your documents

Locked inside your browser before anything is uploaded. We store something we cannot open. The readable version never leaves your computer.

Your data

Never comes to us at all. It moves from your systems to your partner’s. We handle permission and nothing else.

Your source code

Unlocked only inside your own running software, on your own infrastructure. We’re never in the path.

A breach of NakodaX does not expose your work, because we don’t have it.

The details your reviewer will ask for

How things are encrypted
Documents are encrypted on your own device, before upload, using standard, widely audited cryptography. Everything in transit is encrypted. We don’t invent our own algorithms, and we don’t publish a spec sheet here. The full technical detail is in our security documentation, available on request to security@nakodax.com.
Where things are held
Permissions, access rules, and access history are held in [region/provider: e.g. AWS Mumbai and Frankfurt]. The contents of your documents, data and code are not held by us at all. [Confirm regions and whether customers can choose residency.]
Availability
Opening a protected file requires reaching us. That is the mechanism, not a weakness: a file that opens without checking is a file you’ve permanently given away. It also means uptime is a contractual commitment on our side, not a marketing line. [State the SLA once defined.] Brief network interruptions are tolerated by design, so a short outage does not take a customer’s production system down.
Certifications
[State honestly: e.g. “SOC 2 Type I in progress, expected Q4 2026. Our security questionnaire answers are available today.” If nothing is in progress, say what the roadmap is.]
Subprocessors
[List them: cloud provider, email, analytics, payments. Reviewers always ask, and publishing it saves a week of back and forth.]
Reporting a vulnerability
Found something? Tell us at security@nakodax.com. We respond, we fix, and we credit researchers who report responsibly.

What we record

Who opened what, and when. That history belongs to you, and it’s the thing most companies discover they’ve never had.

Your control

Revoke

Withdraw access at any time, effective on the next attempt to open.

Expire

Access that ends on a date you set.

Limit

Cap how many times something can be opened.

Scope

Share only part of a document.

Audit

A record of every open, exportable.

Separate

Every recipient controlled independently.

Where AI is and isn’t involved

We think you should know exactly where any AI touches your work, so here it is.

Your documents and data: never. No AI reads, processes, or trains on them. They’re encrypted before we could, even if we wanted to.

Source protection: optional, and off unless you turn it on. When you protect source code, your developers still need to work against the parts that are now locked. We can optionally generate example inputs and outputs to make that easier.

  • It never sees your actual code. Only the outline of a function: its name, what goes in, what comes out, and the description your own developers wrote.
  • It’s off by default. Nothing is sent anywhere unless you switch it on.
  • You can run it entirely inside your own network, so nothing leaves at all.
  • We never train models on your content. Not your documents, not your data, not your source.

Questions we’re asked

Where is our information held?
Permissions and access rules are held by us. The contents of your documents, data and source are not.
What happens if NakodaX is unavailable?
Access checks depend on reaching us, so we treat availability as a core commitment rather than a feature. We’ll walk through the specifics for your situation on a call.
What happens if we stop being a customer?
You keep your files. We’ll walk you through unlocking everything you hold before the relationship ends. Nothing of yours is held hostage.
Can you produce records for an audit?
Yes. Access history is exportable.
Do you have a security questionnaire on file?
Send us yours. We answer them properly rather than pointing at a portal.

Have a review process?

Send it over. We’d rather answer it than schedule a call about scheduling a call.