NEXARD.

TRUST THROUGH CLARITY

Boundaries are part of the product.

Nexard keeps agents focused, tools scoped, and people in control. This page explains the current preview and the work required before a public launch.

Workspace boundary & tenant isolation

Authenticated sessions query only records matching the owner ID on the server. Automated test suites verify cross-tenant isolation on agents, knowledge, runs, approvals, and deletion requests.

Read-only tool sandbox

Knowledge retrieval is read-only. No arbitrary code execution, external messaging, payment processing, or destructive mutations are enabled in preview.

Secret storage & data flows

Knowledge files and execution metrics are persisted in Cloudflare D1 (APAC region). Provider keys remain in server environment secrets. Source text is treated as untrusted context.

Security headers & content policy

Enforces Content-Security-Policy (CSP), Strict-Transport-Security (HSTS), X-Content-Type-Options: nosniff, Referrer-Policy, and Permissions-Policy across all public routes.

Before production

A public release requires formal third-party penetration testing, legal terms review, and published incident response protocols. No certification is claimed during preview.