NERVE is live across local, private and approved-cloud deployments. Book an evaluation

Governance and claim limits

Policy travels with the information.

NERVE keeps protective handling, privacy sensitivity and authority separate, then evaluates every applicable restriction before discovery or retrieval. Nothing is decided after the fact.

Enforced in the platform

Three separate dimensions

Handling, sensitivity and authority are not the same question

Collapsing these three into a single label is the most common way an information system becomes unsafe. NERVE evaluates each dimension independently and then applies every restriction that results.

Dimension 1

Protective handling

The classification or handling band carried by a record, together with any compartments and caveats that narrow who may see it and how it may be moved.

Dimension 2

Privacy and sensitivity

Policy-profile categories derived from the content, the labels the source supplied, and the version of the mapping that produced the result. Mapping versions matter, because categories change over time.

Dimension 3

Authority and permitted use

The stated purpose, the authority references supplied by the accountable organisation, the operations allowed under them, and the scope and validity period they cover.

Dataset and organisation scope

Records belong to an organisation and a dataset. Scope is the outermost boundary and is evaluated before any other restriction.

Retention

An explicit retention position travels with the record, and a hold can override disposition until it is released.

Use restrictions

Restrictions on onward use, export and derivation are attached to the record itself, not to a user interface that could be bypassed.

Classification is not a substitute for privacy or purpose controls

A record can carry a low classification and still be highly privacy-sensitive. Treating a handling band as a proxy for sensitivity, or for permitted use, is exactly the failure this model prevents.

Policy profiles

Sensitivity categories are explicit and versioned

A policy profile names the sensitivity categories your organisation recognises and the mapping that assigns them. The UK-oriented reference profile uses three categories, and any labels the source already applied are retained alongside them for interoperability rather than overwritten.

Because the mapping has a version, a category assigned last year can be distinguished from one assigned today, and a profile change can be applied as a new assessment rather than a silent rewrite.

PersonalData

Information relating to an identifiable living individual.

SpecialCategoryData

Categories requiring additional protection, carrying a higher justification threshold for use.

CriminalOffenceData

Offence and related proceedings information, handled under its own conditions.

Source labels, for example PII

Retained as supplied for interoperability with upstream systems, and kept distinct from the categories NERVE assigns.

Software classification is not legal compliance

A category assigned by software is an assessment that supports a decision. It does not establish that processing is lawful. That judgement stays with the accountable organisation.

Eight governance commitments

How the model is meant to behave

Each commitment below is enforced in the platform, and each one has a visible consequence you can inspect in the audit trail.

01

Authorise before matching

Access control is applied before results exist, not after. Restrictions are evaluated before hits, totals, facets, suggestions and aggregations are produced, so an inaccessible record cannot leak through a count or an autocomplete. Where optional vector retrieval is enabled, it enforces equivalent pre-search isolation or uses separated indexes. Unrestricted candidate retrieval followed by post-filtering is never used.

02

Preserve authority context

Purpose, licence, consent, warrant and policy references are supplied by the accountable organisation and carried with the acquisition. NERVE records them, surfaces them and enforces the scope they describe. A populated reference does not establish lawfulness; it records the authority the organisation asserted at the time.

03

Keep derivation conservative

Derived outputs inherit the restrictions of their inputs. Where several inputs are combined, the result carries the most restrictive handling and the union of every applicable restriction. Ordinary processing cannot silently down-mark content: reducing a restriction is a governed decision, recorded as such.

04

Respect necessity, proportionality and collateral scope

Supplied decisions about necessity and proportionality are recorded, and the approved scope is enforced. Policy may require that collateral material is minimised, masked, segregated or subject to enhanced justification. These remain governed decisions made by people, not legal conclusions invented by software.

05

Treat source content as hostile

Acquired material is assumed to be adversarial until proven otherwise. Archives are expanded under bounds, parsers run in isolated processors with narrow credentials, and the network posture for parsing is deny-by-default. A malicious document should fail loudly inside a sandbox rather than quietly reach the rest of the platform.

06

Make quarantine explicit

Where scanning is mandatory and the scanner is unavailable, affected content stays quarantined rather than being released on the assumption it is clean. Quarantine enforcement is covered by recorded acceptance evidence.

07

Retain by policy and hold

Retention is explicit, and a hold overrides disposition while it is in force. Authorised deletion includes verified removal from indexes and caches, not only from primary storage. In the reference profile a zero-day default means retain until an authorised disposition decision is made. Releasing a hold resumes policy evaluation rather than triggering immediate deletion.

08

Audit without copying the lake

Audit records are append-oriented, access-controlled and content-minimised, so the audit trail does not become a second uncontrolled copy of the corpus. Queries can be recorded using protected fingerprints instead of raw terms. Ordinary application audit is not claimed to be administrator-proof, and that limit is stated rather than implied.

Shared responsibility

What NERVE enforces, and what your environment owns

Everything on this page is enforced by the platform. Accreditation, physical isolation and regulatory compliance additionally depend on the environment the software runs in, the decisions your organisation makes around it, and the acceptance process you put the deployment through.

That is a product boundary rather than a caveat. NERVE makes the right outcome achievable and the wrong outcome visible; it cannot certify an environment it does not control.

Next step

Bring your own governance model to the table

An evaluation works through your handling bands, policy profile, authority references and retention rules, and ends with the evidence you need before relying on a result.