ENTERPRISE COMPLIANCE
Compliance built in. Not bolted on.
Every project starts with universal sensitive data detection.NexusPort AI then applies the compliance frameworks relevant to what is actually in your data — automatically, regardless of your industry.
20+ compliance frameworks supported
Mapped automatically based on your industry and the data in your estate.
Universal — Every Industry · Every Organization
Sensitive data detection runs on every project. No exceptions.
Personally Identifiable Information exists in every organization — in employee records, customer databases, vendor contacts, and operational documents. NexusPort AI scans every data source for PII automatically, regardless of industry, before a single record is migrated.
50+ PII types detected across structured databases, semi-structured files, and scanned unstructured documents
PERSONAL DATA
Customer & Employee PII
GDPR · CCPA · CPRA · State Privacy Laws
Full Name, Email, Phone, Address, SSN, Passport, IP Address, Device ID, Biometric Data — detected automatically across every data source regardless of industry.
HEALTH DATA
PHI & Medical Records
HIPAA · HITECH · FDA 21 CFR Part 11 · ePHI
Medical Record Numbers, Health Insurance IDs, diagnosis data, treatment records, and patient identifiers — flagged wherever they appear, including in non-healthcare companies.
FINANCIAL DATA
Payment & Financial Records
PCI-DSS · SOX · GLBA · Basel III · FINRA
Credit card data, bank account details, transaction records, financial controls data, and cardholder information — mapped to retention and encryption requirements automatically.
CONTROLLED & RESTRICTED DATA
Government & Export Controlled
ITAR · CMMC Level 2 · FedRAMP · FISMA · NIST SP 800-171 · CUI
Controlled Unclassified Information, export-restricted technical data, and federal compliance requirements — identified across file systems, databases, and document repositories.
CHILDREN & STUDENT DATA
Minor & Education Records
COPPA · FERPA · CCPA · GDPR
Student education records, children's data under 13, and minor-related consent requirements — flagged automatically based on data content, not just company type.
OPERATIONAL & BUSINESS DATA
Contracts, IP & Business Records
SOC 2 · ISO 27001 · GDPR · Contractual Retention
Service agreements, intellectual property, vendor contracts, and business-sensitive records — classified by sensitivity and mapped to retention and access control requirements.
PHI Detection — The Healthcare Subset of PII
Protected Health Information (PHI) is a specific category of PII defined under HIPAA — it is PII that relates to an individual's health condition, healthcare provision, or payment for healthcare. NexusPort AI detects both general PII and the specific PHI subset across all data structures, identifying which records trigger HIPAA obligations and which require only standard PII handling. This distinction matters: a customer email is PII. That same email in a patient record is PHI — and carries significantly stricter handling requirements.
Need help mapping frameworks to your industry or deal type? Our team can walk through your requirements in a 30-minute call.
Talk to Our Team⚠️ When regulations conflict — NexusPort AI shows you, routes to a human decision-maker, and documents the resolution. You own the decision. We make it visible and auditable.
e.g., GDPR erasure right vs. SOX 7-year retention — detected automatically
NexusPort AI identifies data that may be subject to the compliance frameworks listed above and surfaces it for review by your qualified legal, compliance, and security teams. NexusPort AI does not provide legal advice, issue compliance certifications, or replace assessment by qualified professionals. CMMC Level 2 certification requires independent assessment by an accredited C3PAO. ITAR compliance requires registration with the US Directorate of Defense Trade Controls (DDTC). FedRAMP authorization requires assessment by an accredited 3PAO.
ENTERPRISE & COMPLIANCE
Your data never has to leave your boundary.
Choose the AI processing tier your legal and security team requires. We deploy to fit — not the other way around.
Standard API
- →No training on your data
- →Vendor cloud, Zero Data Retention agreement
- →HIPAA BAA available
- →Best for: mid-market, lower-sensitivity data with Zero Data Retention agreements
Private Cloud (Bedrock / Vertex / Azure)
- →Runs inside YOUR AWS, GCP, or Azure tenant
- →Your chosen region — no cross-border transfer
- →No third-party vendor custody of raw data
- →Best for: Fortune 500, HIPAA, financial services
On-Prem / Air-Gapped
- →Your data center, zero external network calls
- →Self-hosted open-weight models
- →Satisfies pre-signing confidentiality and data secrecy requirements
- →Best for: ITAR, defense, classified data
Not sure which tier you need? Our compliance team maps your requirements to the right deployment in a 30-minute call.
Talk to Our Team