What we don’t touch.
This is the document to hand your security or risk team before a Nivaan review starts. It states plainly what we access, what we refuse to ask for, and how any AI-assisted analysis is kept away from your live environment — so the conversation is over in one read, not three meetings.
What we access, refuse, and commit to
Six hours of your time. Four conversations and one data request.
- Read access to billing and usage exports
- One hour each: sponsor, finance, platform lead, engineer
- Up to two weeks of application or usage logs
The review is designed to clear your risk function without a special case.
- Production access, or an agent in your estate
- Customer, member or personal data of any kind
- A procurement exercise, or an internal project team
Fixed fee agreed before we start. No change control, no scope creep.
- Every finding tested with its owner before you see it
- A capped number of reviews running at any one time
- If there is little to find, that is the report you get
On the AI-assisted part of the work
Some analysis in a review is accelerated with AI-assisted tooling — the same category of tool your own engineers are weighing whether to trust with your codebase. Here is exactly how it’s kept away from your systems.
Only the billing and usage exports already handed over for the review. Nothing live, nothing credentialed.
Your infrastructure, your codebase, your production systems. No agent is ever pointed at your estate.
Every AI-assisted finding is checked against source data and against the engineer who owns the line, by the practitioner, before it reaches you. Nothing ships from a model straight to your desk.
Questions this doesn’t answer are exactly what the first call is for.
Twenty minutes, no deck, no follow-up sequence.
Book a 20-minute call