NIC Trust Center
Configuration-derived security, compliance, architecture, and data handling profile for lenders and risk teams.
Last updated: 2026-03-03 | Source: runtime_configuration1 Security Overview
- Encryption in transit: Yes
- Encryption at rest: Yes
- Tenant isolation: Yes
- RBAC enabled: Yes
- Audit logging enabled: Yes
- Retention policy engine: Yes
- Connector KMS provider: local
2 Compliance Roadmap
in_progress.
planned.
future.
3 Architecture Overview
- Multi-tenant isolation: Yes
- Control-plane separation: Yes
- Evidence-first design: Yes
4 Data Handling
- Data residency region: us-east-1
- Data deletion SLA (days): 30
- Retention policy configurable: Yes
- Tenant-scoped storage: Yes
5 Access Control
- Role-based permissions: admin, member, viewer, auditor, platform_admin
- Mode-based UX separation: admin, business, auditor
- Least privilege guidance: Yes
6 Incident Response Summary
Operational alerts, connector failures, and audit anomaly signals.
Containment, investigation, remediation, and tenant impact review.
Customer communication based on severity and contractual obligations.
7 Vendor Risk FAQ
OIDC-based SSO is supported.
Status: configuredTenant-scoped audit logs capture access, ingestion, governance, and workflow actions.
Status: yesDeployment region is configured as 'us-east-1'.
Status: yesData at rest uses platform-managed encryption controls.
Status: yes8 Evidence Links
- KMS Rotation Runbook (runbook)
9 Attestation
This profile is configuration-derived and does not itself certify external compliance.10 Vendor Questionnaire Accelerators
SIG Lite Pre-Answers
Tenant-scoped isolation is enforced across retrieval, storage, and audit boundaries.
Status: readyYes. Tenant-scoped audit trails and export packs are available for compliance workflows.
Status: readyEncryption is enabled in transit and at rest with environment-configured key management.
Status: readyCAIQ Mapping
Application & Interface Security
Status: mappedLogging & Monitoring
Status: mappedEncryption & Key Management
Status: mappedData Flow Summary
Nodes: 5 | Flows: 4documents, transcripts, metadata
parsed text, chunks, audit metadata
tenant-scoped retrieval context
answers, citations, exports
Subprocessors
Model Inference
Reasoning and summarization tasks where enabled by tenant policy.Region: Configurable by deployment | Status: active