Nythrex

Nythrex · Security

Your systems, your keys. Our discipline.

Security in outsourcing starts with a simple principle: the vendor shouldn’t own what it doesn’t need to own. We work in your accounts through access you can revoke, keep secrets out of code and chat, and build security checks into every release.

Access

  • Your identity provider
  • Least privilege
  • MFA
  • Revocable delegation
  • Access reviews

Code & delivery

  • Code review
  • Dependency scanning
  • Secret scanning
  • SAST
  • Signed releases

Infrastructure

  • Infrastructure as code
  • Network segmentation
  • Encryption at rest & in transit
  • Backups

Data & AI

  • Data minimisation
  • Regional processing
  • Provider terms reviewed
  • Audit logs

Our baseline practices

0/9

AI-specific security

  • Documented data flows for every AI feature: which data, which provider, which region, which retention setting.
  • Business-grade provider accounts owned by you — not personal accounts.
  • Prompt-injection defences, least-privilege tools and approvals for agents. See AI agents in production.
  • PII minimisation before model calls where the task allows it. See customer data in LLMs.

Frequently asked questions

Want a second opinion on your project?

Tell us what you’re building and where you’re stuck. We’ll reply within one business day with the most practical next step — even if that step isn’t us.

Start a project