ENTERPRISE

Nexus Legal Enterprise is ready.

Every enterprise capability is already built and activatable on demand. There are no integrations pending development when the first contract lands. Below — what is live today, what activates per client, what is in formal certification.

12 capabilities readyEU-only infrastructureSOC 2 cert Q1 2027Evidence packet under NDA

CAPABILITY MATRIX

What is on the table at signature.

Three states only. Active — in production today. Ready — built and activates the moment the client signs. In progress — controls implemented, formal certification on schedule.

SAML 2.0 SSOready to activateOkta · Azure AD · Google Workspace · OneLogin · Ping · any SAML 2.0 IdP
IP allowlist per API keyactiveper API key, per organization
Row-Level Securityactiverow-level isolation per firm
RBAC rolesactiveauthor · reviewer · approver · admin
Append-only audit logactiveappend-only · 3-year retention
SOC 2 Type II controlsimplemented · cert in progresscontrols CC1-CC9 implemented · observation Q3-Q4 2026 · report expected Q1 2027
CCPA complianceactiveCalifornia Consumer Privacy Act rights live
GDPR + RoPAactiveGDPR + LOPDGDD + RoPA Art. 30
Evidence packet (under NDA)ready to activatevendor register · risk register · policies · audit logs (under NDA)
Pre-signed DPAready to activatepre-signed · 14 sections · 8 documented sub-processors
SLA with credit-backactive99.5 % Standard / 99.9 % Enterprise · automatic credit-back
End-to-end white-labelactiveend-to-end for distributor partners

SECURITY POSTURE

Controls equivalent to regulated financial and healthcare environments.

Zero Retention by default. PII Gatekeeper anonymises identifiers before any upstream LLM call. AES-256 at rest, TLS 1.3 in transit, AES-256-GCM row-level for outputs. All client data infrastructure stays in the EU (Railway europe-west4 + Supabase eu-west-2). Incident response time on active breach: under 1 hour. Customer notification under 24 h. Authority notification under 72 h (GDPR Art. 33).

Need the evidence packet?

Enterprise customers can request the full control evidence pack — vendor register, risk register, policies, audit log samples — under NDA. The package is ready today; it does not wait for the SOC 2 report.

Request the evidence packetsecurity@nexusquantum.legal

Talk to enterprise.

Tell us your firm size, the jurisdictions you need active, your IdP and your DMS. We come back with the activation timeline and the contract documents (DPA, SLA, security review packet) on the same call.