Annual audit — March 2026
Data Processing Agreement available
Personal Data Protection Act compliant
Preparation in progress, target Q4 2026
Every expert identity is protected end-to-end — from call preparation to published intelligence.
Real names are replaced with structured codes (EXP-001, EXP-002…) before any transcript leaves the recording layer. Human reviewers see codes, not names.
Job titles are generalised to seniority + function descriptors: 'Former VP, Asia Logistics' not 'Former VP Operations at [Company]'. Identifiable role combinations are reviewed by our compliance team.
Sector references use tier-1 generic categories: 'Southeast Asian grocery logistics', not a named operator. Case studies and published intelligence never include specific company names or deal identifiers.
Our AI review layer flags 94% of potential re-identification vectors before human review. Anything above a 0.4 risk score is escalated to our compliance team before the call is released to analysts.
Three roles — Owner, Editor, Viewer — with granular permissions per action.
| Action | Owner | Editor | Viewer |
|---|---|---|---|
| View projects and claims | ✓ | ✓ | ✓ |
| Add expert calls | ✓ | ✓ | ✗ |
| Edit thesis and annotations | ✓ | ✓ | ✗ |
| Export claim ledgers / reports | ✓ | ✓ | ✗ |
| Manage project members | ✓ | ✗ | ✗ |
| Delete calls or projects | ✓ | ✗ | ✗ |
| Access API keys | ✓ | ✗ | ✗ |
We follow a three-phase response protocol for security incidents.
Detection & triage
Containment
Customer notification
Regulatory notification: < 72 hours per GDPR Art. 33
We maintain a responsible disclosure programme for security researchers. If you discover a potential vulnerability, email security@nextyn.com with a description, reproduction steps, and your contact details. We respond to all valid reports within 5 business days and coordinate a disclosure timeline with the reporter. We do not pursue legal action against good-faith researchers following responsible disclosure guidelines.
We provide compliance documentation to qualified enquirers for due diligence and vendor assessment.