Security & trust

Governance is not an add-on here — it's part of the generation pipeline.

Identity, an audit trail that can't be quietly edited, and compliance evaluation run against your actual infrastructure state, not a marketing checklist.

Identity and access

SAML/SSO and OIDC federated login, SCIM provisioning that keeps access in sync with your identity provider, and role-based access control scoped per tenant and per environment — not a single global admin/member split.

Sealed audit trail

Every action is recorded in a hash-chained audit log: each entry cryptographically references the hash of the one before it, so tampering or deletion is detectable rather than silently possible. Reviewable by your team and auditors, never editable, and exportable for SIEM ingestion.

Regulatory compliance evaluation

16 frameworks — including SOC 2, HIPAA, PCI-DSS, GDPR, ISO 27001, DORA, and NIS2, plus CIS Benchmarks for AWS, Azure, and GCP and regional privacy laws — evaluated live against your actual Terraform plans. Violations are found by parsing real plan and state resources against each framework's controls, not read off a static checklist.

What this page doesn't claim: NebulaStack does not yet publish a completed third-party audit report (SOC 2 Type II, ISO 27001 certification) — those are processes with a real timeline, not something to imply before it's true. If a specific attestation is a requirement for your evaluation, contact us directly and we'll tell you exactly where that stands.

See the governance model in the product

Free to start, no credit card.