Skip to content
Help find missing people.→

[SEC] — Posture

Trust is the product.

Intelligence platforms hold what must not leak. Newrali is engineered from the first migration for isolation, least privilege, and accountability — not retrofitted for them.

[01] — Principles

Five commitments, enforced in code.

[01] — Isolation

Isolation by architecture

Workspaces are hard tenant boundaries enforced at the database layer with row-level security. Module and team scopes narrow access further — every query is scoped, and cross-tenant leakage is treated as the primary failure mode to design against.

ISOLATION — TENANT BOUNDARIES RLS ACTIVE WORKSPACE — NORTH RIDGE SCOPE: WS-A · ENFORCED AT THE DATABASE WS — B SEALED WS — C SEALED DENIED · CROSS-TENANT EVERY QUERY SCOPED · BY ARCHITECTURE, NOT CONVENTION
[02] — Authorization

Least privilege, centrally decided

Every request is evaluated by a central policy engine (Cedar). Permissions are explicit, fine-grained, and auditable. Anything the interface shows you is a hint — the backend independently enforces the decision.

AUTHORIZATION — POLICY ENGINE CEDAR REQUEST WHO — U-042 DO — INV:VIEW ON — INV-7 EVALUATE permit ( principal in Team::"analysts",   action == Action::"investigation:view" ) when { resource.workspace == principal.workspace }; ✓ PERMIT ✕ FORBID EVERY REQUEST · DECIDED CENTRALLY · NEVER CLIENT-SIDE
[03] — Accountability

Accountability built in

Mutations to intelligence products are audited, and authorization decisions leave a trail. Finished work traces back through its revisions to the sources it rests on.

AUDIT — CHAINED HISTORY LIVE 09:14 SOURCE.ACCEPT ANALYST·03 #2E71…A4 ↳ PREV #90C4…1B 11:47 GRAPH.LINK ANALYST·02 #B03D…77 ↳ PREV #2E71…A4 14:02 REPORT.PUBLISH ANALYST·01 #8F42…C1 ↳ PREV #B03D…77 · 47 SOURCES IN SCOPE 14:03 SHARE.CREATE ANALYST·01 #44AE…9D ↳ PREV #8F42…C1 16:20 ROLE.GRANT ADMIN·01 #D18B…E2 ↳ PREV #44AE…9D CHAIN VERIFIED ✓ WHO · WHAT · WHEN · ON WHICH SOURCE
[04] — Primitives

Proven primitives only

Modern authentication with passkeys and two-factor support. Cryptographically random share tokens — never guessable identifiers. Encryption in transit and at rest.

PRIMITIVES — PROVEN ONLY STANDARD AUTHENTICATION PASSKEYS ✓   2FA ✓ IN TRANSIT TLS 1.3 · FORWARD SECRECY AT REST AES-256 · ENCRYPTED VOLUMES TOKENS & LINKS csprng(32) → nQ7xK…v4Dw2 UNGUESSABLE · 256-BIT NO HOME-ROLLED CRYPTO · NO GUESSABLE IDENTIFIERS
[05] — Ownership

Your data, on your terms

Export what's yours, when you choose, and run the entire platform where your mandate requires: our cloud or your own metal today, with a zero-trust private cloud and fully air-gapped deployment coming soon.

OWNERSHIP — YOUR TERMS PORTABLE YOUR WORKSPACE PRINT-READY PDF READY ✓ FULL DATA EXPORT YOURS, ALWAYS ✓ SELF-HOSTED · BY BRIEFING AIR-GAPPED · SOON → YOUR DATA LEAVES WHEN YOU SAY SO — NOT WHEN A VENDOR DOES

[02] — Controls

Hardened down to the machine.

The principles above govern the platform. These controls govern the machines that run it.

  • 01

    Hardened to the DISA STIG profile at install: SELinux enforcing, the audit daemon running, and unneeded services removed.

  • 02

    Reached over SSH with Ed25519 keys, and only through a private encrypted network. The SSH port is closed to the internet.

  • 03

    Closed to inbound traffic: public requests arrive through an outbound-only tunnel, and every service listens on localhost alone.

  • 04

    Rootless: the stack runs under an unprivileged service account with no login shell, and drops privileges again inside each container.

  • 05

    Encrypted to the database: TLS 1.3 with SCRAM authentication, and unencrypted connections refused.

  • 06

    Private certificate authority in every deployment, with internal certificates renewed automatically.

  • 07

    Backed up continuously: database changes are archived as they happen and encrypted with AES-256 before they leave the host.

  • 08

    Dedicated for enterprise: each enterprise customer gets its own host, database, certificate authority and secrets.

01 / 08

[03] — Disclosure

What's live. What's ahead.

Security claims should be checkable. Here is where the platform stands today — and what we're building next, stated plainly.

Shipped — in the platform today

  • ✓ Workspace isolation with row-level security
  • ✓ Central policy-based authorization on every request
  • ✓ Audited mutations on intelligence products
  • ✓ Passkeys & two-factor authentication
  • ✓ Encrypted transport and storage
  • ✓ Cryptographically random share links with revocation
  • ✓ Structured review before anything enters the record
  • ✓ Self-hosted enterprise deployment on your own infrastructure

◌ In development — the enterprise road

  • → Zero Trust Private Cloud and air-gapped deployment
  • → Offline, signed licensing — no phone-home required
  • → Tamper-evident builds and supply-chain hardening
  • → Hash-chained, exportable audit history

◆ Commitment to transparency

Verify us — don't take our word for it.

Security claims you can't check are just marketing. Our latest independent penetration-test report is available on request — read what the testers found, not what we chose to say.

Request the pentest report →

Found something? We take reports seriously and respond fast — reach the team privately through the community or from inside your account.

Bring work that matters.

Run it on an architecture that takes it as seriously as you do.