NERVE is live across local, private and approved-cloud deployments. Book an evaluation
Governance and claim limits
Policy travels with the information.
NERVE keeps protective handling, privacy sensitivity and authority separate, then evaluates every applicable restriction before discovery or retrieval. Nothing is decided after the fact.
Enforced in the platform
Three separate dimensions
Handling, sensitivity and authority are not the same question
Collapsing these three into a single label is the most common way an information system becomes unsafe. NERVE evaluates each dimension independently and then applies every restriction that results.
Dimension 1
Protective handling
The classification or handling band carried by a record, together with any compartments and caveats that narrow who may see it and how it may be moved.
Dimension 2
Privacy and sensitivity
Policy-profile categories derived from the content, the labels the source supplied, and the version of the mapping that produced the result. Mapping versions matter, because categories change over time.
Dimension 3
Authority and permitted use
The stated purpose, the authority references supplied by the accountable organisation, the operations allowed under them, and the scope and validity period they cover.
Dataset and organisation scope
Records belong to an organisation and a dataset. Scope is the outermost boundary and is evaluated before any other restriction.
Retention
An explicit retention position travels with the record, and a hold can override disposition until it is released.
Use restrictions
Restrictions on onward use, export and derivation are attached to the record itself, not to a user interface that could be bypassed.
Classification is not a substitute for privacy or purpose controls
A record can carry a low classification and still be highly privacy-sensitive. Treating a handling band as a proxy for sensitivity, or for permitted use, is exactly the failure this model prevents.
Policy profiles
Sensitivity categories are explicit and versioned
A policy profile names the sensitivity categories your organisation recognises and the mapping that assigns them. The UK-oriented reference profile uses three categories, and any labels the source already applied are retained alongside them for interoperability rather than overwritten.
Because the mapping has a version, a category assigned last year can be distinguished from one assigned today, and a profile change can be applied as a new assessment rather than a silent rewrite.
PersonalData
Information relating to an identifiable living individual.
SpecialCategoryData
Categories requiring additional protection, carrying a higher justification threshold for use.
CriminalOffenceData
Offence and related proceedings information, handled under its own conditions.
Source labels, for example PII
Retained as supplied for interoperability with upstream systems, and kept distinct from the categories NERVE assigns.
Software classification is not legal compliance
A category assigned by software is an assessment that supports a decision. It does not establish that processing is lawful. That judgement stays with the accountable organisation.
Eight governance commitments
How the model is meant to behave
Each commitment below is enforced in the platform, and each one has a visible consequence you can inspect in the audit trail.
01
Authorise before matching
Access control is applied before results exist, not after. Restrictions are evaluated before hits, totals, facets, suggestions and aggregations are produced, so an inaccessible record cannot leak through a count or an autocomplete. Where optional vector retrieval is enabled, it enforces equivalent pre-search isolation or uses separated indexes. Unrestricted candidate retrieval followed by post-filtering is never used.
02
Preserve authority context
Purpose, licence, consent, warrant and policy references are supplied by the accountable organisation and carried with the acquisition. NERVE records them, surfaces them and enforces the scope they describe. A populated reference does not establish lawfulness; it records the authority the organisation asserted at the time.
03
Keep derivation conservative
Derived outputs inherit the restrictions of their inputs. Where several inputs are combined, the result carries the most restrictive handling and the union of every applicable restriction. Ordinary processing cannot silently down-mark content: reducing a restriction is a governed decision, recorded as such.
04
Respect necessity, proportionality and collateral scope
Supplied decisions about necessity and proportionality are recorded, and the approved scope is enforced. Policy may require that collateral material is minimised, masked, segregated or subject to enhanced justification. These remain governed decisions made by people, not legal conclusions invented by software.
05
Treat source content as hostile
Acquired material is assumed to be adversarial until proven otherwise. Archives are expanded under bounds, parsers run in isolated processors with narrow credentials, and the network posture for parsing is deny-by-default. A malicious document should fail loudly inside a sandbox rather than quietly reach the rest of the platform.
06
Make quarantine explicit
Where scanning is mandatory and the scanner is unavailable, affected content stays quarantined rather than being released on the assumption it is clean. Quarantine enforcement is covered by recorded acceptance evidence.
07
Retain by policy and hold
Retention is explicit, and a hold overrides disposition while it is in force. Authorised deletion includes verified removal from indexes and caches, not only from primary storage. In the reference profile a zero-day default means retain until an authorised disposition decision is made. Releasing a hold resumes policy evaluation rather than triggering immediate deletion.
08
Audit without copying the lake
Audit records are append-oriented, access-controlled and content-minimised, so the audit trail does not become a second uncontrolled copy of the corpus. Queries can be recorded using protected fingerprints instead of raw terms. Ordinary application audit is not claimed to be administrator-proof, and that limit is stated rather than implied.
Shared responsibility
What NERVE enforces, and what your environment owns
Everything on this page is enforced by the platform. Accreditation, physical isolation and regulatory compliance additionally depend on the environment the software runs in, the decisions your organisation makes around it, and the acceptance process you put the deployment through.
That is a product boundary rather than a caveat. NERVE makes the right outcome achievable and the wrong outcome visible; it cannot certify an environment it does not control.
Next step
Bring your own governance model to the table
An evaluation works through your handling bands, policy profile, authority references and retention rules, and ends with the evidence you need before relying on a result.