Your data stays in your control

Needl.ai runs in your own cloud account, on premise, or in a dedicated instance we operate for you. It follows your permissions, never trains on your data, and is independently audited for SOC 2 Type II and certified to ISO 27001.

How your data stays yours

The same commitments apply in every deployment.

Never used for training

Your documents, questions and outputs are never used to train any model, ours or a model provider's.

Encrypted in transit and at rest

Data is encrypted in transit with TLS 1.2 or higher and at rest with managed keys. Credentials for your connected systems are encrypted with AES-256.

Every answer traceable

Each finding links to the page it came from, so a reviewer can open the source and check it.

Activity on record

Questions, answers and the sources behind them are kept on record. In your own cloud, infrastructure activity lands in your own logs.

Deleted on request

Ask us and we delete your documents, indexes and everything derived from them, then confirm it in writing.

Single sign-on

Sign in with your Microsoft account, so access follows your identity provider.

Deploy where your data already lives

Three ways to run Needl.ai, each with the same security controls. Start in our cloud and move into your own environment when you are ready.

The Needl.ai cloud, with each organisation's data kept separate, encrypted and access-controlled

Needl.ai cloud

Our managed cloud. Each organisation's data is kept separate, encrypted and access-controlled under our SOC 2 Type II and ISO 27001 controls.

Runs in
Needl.ai's managed cloud
Operated by
Needl.ai
Best for
Trials and fast starts
A dedicated instance with its own compute, storage and network, reserved for one customer and operated by Needl.ai

Dedicated instance

A single-tenant deployment reserved for you, with its own infrastructure and no compute or storage shared with anyone else. We operate it for you.

Runs in
Infrastructure reserved for you
Operated by
Needl.ai
Best for
Isolation without running it yourself
Needl.ai installed inside your own cloud account or servers, with your keys, network rules and logs, and no document leaving your perimeter

Your cloud or on premise

Installed in your own AWS or Azure account, or on your own servers. Your keys, your network rules and your logs. No document leaves your perimeter.

Runs in
Your AWS or Azure account, or on premise
Operated by
You, with our team alongside
Best for
Data that must stay inside your network

Protection built into every answer

Security sits in the product as well as the infrastructure. Three safeguards are part of the platform itself.

Permission-aware answers: what each person can open in the source system decides which files an answer may use

Permission-aware by design

Needl.ai reads each document with the access every person has in the source system and records who can open it. Every search and answer is filtered by that record, so people only get results from files they could already open.

  • Access mirrors your source systems
  • Filtered on every search and answer
  • Each organisation's data kept separate
Safeguards in front of the model: injection screening and access scoped to the signed-in user, with an attempt to reach another client's context stopped

Safeguards before the model

A guardrails service sits in front of the language model, and each application switches on the checks it needs. A dedicated detection model screens prompts for injection attempts. What an assistant can reach is fixed by who is signed in, so a prompt cannot change it, and attempts to switch to another client's context are rejected.

  • Prompt-injection screening
  • Access scoped to the signed-in user
  • AI disclosure in every app
Your data and workflows kept separate from the model, which can be switched between approved models, including one in your own cloud account

Your choice of model

Needl.ai keeps your data and workflows separate from the model underneath. Run on the model your firm has approved, including models hosted in your own cloud account. If a provider changes its terms or access, we switch models with no change to your data or workflows.

  • Works with the leading frontier models
  • Runs on models in your own cloud account
  • No rework when models change

Independently audited

Our controls are tested by independent auditors, and the reports are available under NDA.

SOC 2 Type II

An independent audit of how our security controls operate over time. Report available under NDA.

ISO/IEC 27001

A certified information security management system, with annual surveillance audits.

CASA

Google's Cloud Application Security Assessment, for the connectors that read Gmail and Google Drive.

GDPR

Personal data handled in line with the GDPR, with a data processing agreement available on request.

Penetration testing

Independent vulnerability assessment and penetration testing. Summary available under NDA.

ISO/IEC 42001

The international standard for AI management systems. Our certification audit is in progress.

Trusted in regulated environments

“Needl.ai gave us enterprise-grade assurance, no compliance risks, no shadow AI, and complete control over our data environment.”
Chief Investment Officer, Fortune 500 company
  • 27,000 usersAt a Big Four firm, deployed behind its firewall.
  • AWS and AzureDeployable inside your own VPC on either cloud.
  • Security review passedA leading credit rating agency's information security assessment, now running as a dedicated instance.

Frequently asked questions

What security and risk teams ask before approving Needl.ai.

Where does our data live?

Where you choose: in your own AWS or Azure account or on premise, in a dedicated instance reserved for you, or in the Needl.ai cloud. You can start in our cloud and move into your own environment later.

Do you train models on our data?

No. Your documents, questions and outputs are never used to train any model, ours or a model provider's.

Which models do you use, and can we choose?

Needl.ai works with the leading frontier models and can run on the model your firm has approved, including models hosted in your own cloud account. Your data and workflows stay separate from the model, so a switch needs no change on your side.

Who at Needl.ai can access our data?

In your own cloud or on premise, only the people you grant access. In a dedicated instance or the Needl.ai cloud, access is limited to authorised Needl.ai staff who need it to run the service, under the controls audited for SOC 2 Type II and ISO 27001.

How do permissions work?

Needl.ai records who can open each document in the source system and filters every search and answer by that record. People only get results from files they could already open. The context infrastructure note explains how.

Can you delete our data?

Yes. Ask us and we delete your documents, indexes and everything derived from them, then confirm it in writing.

Will you sign our NDA?

Yes. We sign a mutual NDA before any data is shared, and provide a data processing agreement for your review.

Can we review your SOC 2 report and penetration test?

Yes. Our SOC 2 Type II report, ISO 27001 certificate, CASA letter and penetration test summary are available under NDA.

Everything your security team will ask for

One request covers the full pack. We share it under NDA and can walk your risk and compliance teams through the details.

  • SOC 2 Type II report
  • ISO/IEC 27001 certificate
  • CASA assessment letter
  • Penetration test summary
  • Information security policy
  • Data processing agreement
  • Mutual NDA
  • Completed security questionnaires
The security document pack: the SOC 2 Type II report, the ISO/IEC 27001 certificate, the CASA letter, a penetration test summary, the data processing agreement and completed questionnaires