Card data
PCI DSS v4
Card numbers are protected on your premises before anything reaches Neody.
The goal is that Neody stays out of your PCI scope: cardholder data is sealed so the platform cannot read it, and the model sees only a format-preserving stand-in.
Available. We say “out of your PCI scope” only with a QSA scoping opinion in writing — ask us about its status.
Health data
HIPAA
Minimum necessary, enforced per field, per agent.
Each agent sees only the PHI its task requires, on stand-ins wherever possible; every access is recorded with its purpose.
Available. HIPAA is a contract as well as controls — ask us about BAA readiness and terms.
Inside information
MNPI · Reg FD
Only the deal team's agents see the deal.
Access scoped to named people and data classes, wall-crossing and restricted lists enforced at run time, and a record of who saw what and when.
We detect MNPI and enforce barriers — and state the limits plainly: there is no checksum for materiality.
Personal data
GLBA · state privacy laws
The model reasons over stand-ins, not your customers.
Names, SSNs, account numbers and addresses are tokenized consistently, so the model can still match and compare records without seeing who they are.
Available.