Niteron Logo

Security

Useful access. Clear decisions.

Connected tools can read information and make changes. Niteron separates account access, action approval, and results. These controls reduce risk; they do not make an AI system infallible.

Last updated September 13, 2026

01

Account-scoped access

Text chat requests are tied to the signed-in account, and chat and confirmation records are checked for ownership. These application controls do not mean your data is inaccessible to Niteron or its infrastructure providers.

02

Credentials outside chat

Sign-in uses Amazon Cognito. Google app connections use provider authorization, with connector tokens obtained on the server rather than requested in chat. Do not paste passwords, one-time codes, API keys, or payment credentials. Secret material included in a message or document is not guaranteed to be automatically removed.

03

Access is not action approval

Connecting a Google app requests its supported permissions together. In text chat, supported connector writes pause for a Confirmation tied to the exact tool call and your account. Routine read-only lookups do not require a new decision each time. These controls operate at tool-call level, not as an independent review of every network request.

04

Untrusted content and model limits

Emails, web pages, documents, and tool responses can contain misleading instructions. Niteron's prompt tells it to treat that content as data, not authority; tool authorization is enforced separately in code. Neither prompts nor guardrails guarantee immunity to prompt injection. Review destinations, recipients, and changes before approving an action.

05

Where information is processed

Niteron uses cloud services for application data, files, agent execution, and memory. Content needed for a response or requested operation is processed by the relevant model or service provider. This is not local-only processing or a dedicated private computer for each person. See the privacy policy for data-use and retention commitments.

06

Deletion has separate scopes

Chat history, long-term memory, connected accounts, and files are managed separately. Removing a chat does not revoke a connector grant, undo an external action, or erase documents in a connected service. For a broader data request, use the Data & privacy option on the contact page; do not assume every copy is removed by one delete button.

07

Reporting a vulnerability

If you believe you have found a security vulnerability, email security@niteron.com with enough detail to reproduce it. Please give us a reasonable opportunity to fix the issue before disclosing it publicly. We do not pursue legal action against researchers acting in good faith.

Just ask Niteron.

Personal Intelligence