Brand logo of nubesti
  • Home
  • AI Red Team
    • Autonomous Agents

      After KYC and authorization, agents can run scheduled assessments on assets you designate.

    • MITRE ATT&CK mapping

      Testing workflows mapped to MITRE ATT&CK techniques. Mapping is not a claim that every technique ran.

    • OWASP mapping

      Checks mapped to OWASP risk classes, with evidence a reviewer can accept or reject.

    • Integration

      Connect seamlessly with your existing tools and workflows.

    Experience AI Red Team Testing

    See how our autonomous AI agents identify vulnerabilities in your systems.

    Book a Demo
  • Resources
    • Trust Center
    • Methodology
    • Pricing
    • FAQ
    • Blog
  • Contact
    • french
    • spanish
    • portuguese
  • Sign in
  • french
  • spanish
  • portuguese
Sign in
  1. Home
  2. /
  3. Security

Platform security

What we can say about how Nubesti is run — and what we will not invent.

This page is for CISOs and security engineers. It repeats only controls already stated in our legal security materials or that are observable on this site. Internal architecture that is not published stays unpublished.

Nubesti LLC · Delaware, United States

Where this sits

The marketing site and customer portal are separate from customer-designated targets. Binding overview: Security overview. Trust index: Trust Center.

What we state today

  • TLS 1.2+ on production web properties, served through Cloudflare, with security headers
  • Data in transit encrypted with TLS
  • Data at rest encrypted with industry-standard algorithms (AES-256 where we control the store)
  • Administrative access uses unique identities and multi-factor authentication
  • Role-based access in the product so customers can limit who launches tests or sees reports
  • Logging of security-relevant events for investigation
  • Backups of platform configuration and workspace data, access-restricted, retained for a limited rotation
  • Customer Personal Data deleted from production within 60 days after termination, except rotating encrypted backups or legal holds (DPA)

Authorization and scope

Tests require a designated scope, asset ownership or written owner permission, and completed paid KYC. We design the platform so authorized testing of your systems does not become unauthorized access to anyone else’s. Tenant isolation, least privilege, and auditability are baseline requirements — not a certification claim.

Emergency contact and revocation are described in the authorization letter. Running jobs are halted as soon as reasonably possible after you stop them in the portal.

What we do not publish here

We do not publish a full agent-runtime diagram, secret-store internals, exact evidence retention schedules beyond the DPA window, or a claim that Nubesti never holds credentials. Those topics belong in a scoped architecture review.

Email [email protected] for a written briefing under NDA. If a control is not listed above, assume it is not a public claim.

Human accountability

Autonomous testing still runs under Rules of Engagement, customer authorization, KYC, and acceptable use. Platform abuse and unauthorized targeting can be reported to [email protected].

Brand logo of nubesti

Nubesti LLC provides continuous autonomous security testing against customer-authorized assets. Tests require paid KYC.

  • linkedin

Product

  • Platform
  • Methodology
  • Pricing
  • Demo

Trust

  • Trust Center
  • Platform security
  • Customers
  • Vulnerability disclosure

Legal

  • Legal center
  • Privacy
  • DPA
  • Subprocessors
  • Legal notice
  • About
  • Legal
  • Privacy Policy
  • Legal Notice
  • © 2026 Nubesti LLC
  • All rights reserved