Nythrex · Security
Your systems, your keys. Our discipline.
Security in outsourcing starts with a simple principle: the vendor shouldn’t own what it doesn’t need to own. We work in your accounts through access you can revoke, keep secrets out of code and chat, and build security checks into every release.
Access
- Your identity provider
- Least privilege
- MFA
- Revocable delegation
- Access reviews
Code & delivery
- Code review
- Dependency scanning
- Secret scanning
- SAST
- Signed releases
Infrastructure
- Infrastructure as code
- Network segmentation
- Encryption at rest & in transit
- Backups
Data & AI
- Data minimisation
- Regional processing
- Provider terms reviewed
- Audit logs
Our baseline practices
0/9
AI-specific security
- Documented data flows for every AI feature: which data, which provider, which region, which retention setting.
- Business-grade provider accounts owned by you — not personal accounts.
- Prompt-injection defences, least-privilege tools and approvals for agents. See AI agents in production.
- PII minimisation before model calls where the task allows it. See customer data in LLMs.
Frequently asked questions
Keep reading
NythrexHow we workThe Nythrex delivery model: five phases, working demos, forecast ranges, priced change requests, early risks and client ownership of code and cloud.GuideCustomer data in LLMs: GDPR guidePersonal data and LLM APIs: lawful basis, DPAs, transfers, data residency, retention and minimisation — a practical checklist for product teams.GuideWho really owns your code?Paying for software doesn’t make it yours. The clauses that decide code ownership: IP assignment, background IP, open source, AI assets, exit terms.ServiceCloud & DevOpsCloud & DevOps in your own Azure or AWS account: infrastructure as code, CI/CD, observability, security and cost control — documented for your team.
Want a second opinion on your project?
Tell us what you’re building and where you’re stuck. We’ll reply within one business day with the most practical next step — even if that step isn’t us.
