ENTERPRISE COMPLIANCE

Compliance built in. Not bolted on.

Every project starts with universal sensitive data detection.NexusPort AI then applies the compliance frameworks relevant to what is actually in your data — automatically, regardless of your industry.

20+ compliance frameworks supported

Mapped automatically based on your industry and the data in your estate.

PIIPHIPCI-DSSHIPAAHITECHSOXGDPRCCPA

Universal — Every Industry · Every Organization

Sensitive data detection runs on every project. No exceptions.

Personally Identifiable Information exists in every organization — in employee records, customer databases, vendor contacts, and operational documents. NexusPort AI scans every data source for PII automatically, regardless of industry, before a single record is migrated.

Full Name · Email Address · Phone Number · Home AddressDate of Birth · SSN / Tax ID · Passport NumberDriver's License · IP Address · Device ID
Bank Account · Credit Card · Biometric DataMedical Record # · Health Insurance IDSignature · Vehicle ID · GeolocationEmployment Records · Photos / Images

50+ PII types detected across structured databases, semi-structured files, and scanned unstructured documents

Customer & Employee PII

GDPR · CCPA · CPRA · State Privacy Laws

Full Name, Email, Phone, Address, SSN, Passport, IP Address, Device ID, Biometric Data — detected automatically across every data source regardless of industry.

PHI & Medical Records

HIPAA · HITECH · FDA 21 CFR Part 11 · ePHI

Medical Record Numbers, Health Insurance IDs, diagnosis data, treatment records, and patient identifiers — flagged wherever they appear, including in non-healthcare companies.

Payment & Financial Records

PCI-DSS · SOX · GLBA · Basel III · FINRA

Credit card data, bank account details, transaction records, financial controls data, and cardholder information — mapped to retention and encryption requirements automatically.

Government & Export Controlled

ITAR · CMMC Level 2 · FedRAMP · FISMA · NIST SP 800-171 · CUI

Controlled Unclassified Information, export-restricted technical data, and federal compliance requirements — identified across file systems, databases, and document repositories.

Minor & Education Records

COPPA · FERPA · CCPA · GDPR

Student education records, children's data under 13, and minor-related consent requirements — flagged automatically based on data content, not just company type.

Contracts, IP & Business Records

SOC 2 · ISO 27001 · GDPR · Contractual Retention

Service agreements, intellectual property, vendor contracts, and business-sensitive records — classified by sensitivity and mapped to retention and access control requirements.

PHI Detection — The Healthcare Subset of PII

Protected Health Information (PHI) is a specific category of PII defined under HIPAA — it is PII that relates to an individual's health condition, healthcare provision, or payment for healthcare. NexusPort AI detects both general PII and the specific PHI subset across all data structures, identifying which records trigger HIPAA obligations and which require only standard PII handling. This distinction matters: a customer email is PII. That same email in a patient record is PHI — and carries significantly stricter handling requirements.

Need help mapping frameworks to your industry or deal type? Our team can walk through your requirements in a 30-minute call.

Talk to Our Team

⚠️ When regulations conflict — NexusPort AI shows you, routes to a human decision-maker, and documents the resolution. You own the decision. We make it visible and auditable.

e.g., GDPR erasure right vs. SOX 7-year retention — detected automatically

NexusPort AI identifies data that may be subject to the compliance frameworks listed above and surfaces it for review by your qualified legal, compliance, and security teams. NexusPort AI does not provide legal advice, issue compliance certifications, or replace assessment by qualified professionals. CMMC Level 2 certification requires independent assessment by an accredited C3PAO. ITAR compliance requires registration with the US Directorate of Defense Trade Controls (DDTC). FedRAMP authorization requires assessment by an accredited 3PAO.

ENTERPRISE & COMPLIANCE

Your data never has to leave your boundary.

Choose the AI processing tier your legal and security team requires. We deploy to fit — not the other way around.

Fastest to deploy

Standard API

  • No training on your data
  • Vendor cloud, Zero Data Retention agreement
  • HIPAA BAA available
  • Best for: mid-market, lower-sensitivity data with Zero Data Retention agreements
RECOMMENDED FOR ENTERPRISE

Private Cloud (Bedrock / Vertex / Azure)

  • Runs inside YOUR AWS, GCP, or Azure tenant
  • Your chosen region — no cross-border transfer
  • No third-party vendor custody of raw data
  • Best for: Fortune 500, HIPAA, financial services

On-Prem / Air-Gapped

  • Your data center, zero external network calls
  • Self-hosted open-weight models
  • Satisfies pre-signing confidentiality and data secrecy requirements
  • Best for: ITAR, defense, classified data

Not sure which tier you need? Our compliance team maps your requirements to the right deployment in a 30-minute call.

Talk to Our Team