Security

AI agents with system access. You stay in control.

nara executes actions in your systems. That is why every execution is approved, checked in advance, and fully logged.

Evidence

Certified, in Germany, without compromise

ISO 27001 certified

Our information security management is certified to ISO 27001.

Hosted and developed in Germany

The platform is developed and operated in Germany.

GDPR compliant

Personal data is processed under European data protection law.

No training on customer data

Your data is never used to train AI models.

Encrypted throughout

Data is encrypted in transit and at rest.

Contract partner in Germany

Your contract partner is nara GmbH, based in Würzburg, Germany.

Access control

You decide who can do what. Down to the individual resource.

SSO with automatic provisioning

Sign in via SAML and OIDC. Users are provisioned automatically on first login, with no manual account maintenance.

Roles down to resource level

Permissions apply not just globally but down to the individual resource. Access to agents, tools, tickets, and knowledge is open or restricted per area.

Every decision explains itself

Access checks document every decision with a reason: allowed or denied, and why. No black box, no guesswork in an audit.

Execution

Agents act only within clear boundaries

Approvals per tool

Critical actions require human confirmation. You define per tool what an agent may execute on its own and what it may not.

Server tokens without attack surface

Tokens are stored only as SHA-256 hashes, shown exactly once, and can be revoked immediately. Three token types cover different scenarios, including one-time tokens.

Edge Connector: outbound only

The Edge Connector connects internal systems through outbound connections only. No open inbound ports, no new holes in your firewall.

Transparency

Every action leaves a trace

Activity logs capture every agent action, every tool execution, and every ticket step. You can see at any time what an agent did, with which permissions, and with what result.

This is more than a feature for emergencies. It is the foundation for expanding automation step by step: observe first, then trust, then scale.

EU AI Act

No badges, just built-in control

We do not decorate ourselves with blanket compliance promises. What we can say: transparency, traceability, and human control are built into nara, not retrofitted. Every decision comes with a reason, every action is logged, and critical steps require approvals.

We define the details on hosting, data processing, and contracts transparently with you before you start. The result is a verifiable solution instead of a logo on a website.

Convince your security team before it asks.

In the demo, we show the access model, approvals, and logs live. On request, you receive our security documentation in advance.