Security and governance

Built for legal-grade evidence, tenant-safe data products, and enterprise controls.

NADIR serves high-accountability environments where ADAS events can become litigation, claims, or compliance artifacts. Control surfaces are designed for provable lineage, strict tenant boundaries, and policy-governed external data sharing.

Tenant isolation

Data boundaries are enforced at organization and role scope across ingestion, processing, and output layers.

  • Scoped API tokens and least-privilege access controls.
  • Organization-specific event partitioning.
  • Partner-specific permission domains.

Evidence integrity

Every intervention is linked to immutable event lineage from detection through workflow closure.

  • Tamper-evident timeline identifiers.
  • Signed workflow state transitions.
  • Defensible export bundles for claims and legal teams.

Identity and access (Clerk)

Console and onboarding authenticate through Clerk (SOC 2 Type II) with a NADIR org tenancy layer. Passwords for pilot demos may still use legacy local auth when Clerk is disabled — production enables Clerk SSO only.

  • Clerk handles sign-in, MFA, and session JWT issuance.
  • NADIR maps Clerk users to organization_id with sandbox API keys per tenant.
  • Org-scoped object storage for onboarding CSV and evidence attachments.
  • Webhook rotation via Clerk dashboard — see api/auth/CLERK_SETUP.md.

Risk API governance

Dynamic risk outputs are generated using aggregation safeguards that prevent raw tenant exposure.

  • Aggregation thresholds and anonymity controls.
  • Policy-based retention and redaction rules.
  • Audit paths for external data releases.

Control matrix

Representative controls by platform layer.

LayerControlAssurance outcome
Console authClerk SSO + org JWT exchangeEnterprise identity without shared passwords
Object storageOrg-scoped upload ACLTenant-safe file attachments
Ingestion gatewaySigned webhook validationTrusted provider source integrity
Inference servicesVersioned and reproducible scoring pipelineDefensible risk decision lineage
Evidence graphImmutable timeline persistenceLitigation-ready traceability
Risk API layerAggregation and redaction policy checksTenant-safe external distribution