Skip to content
Security and responsible AI

Precise controls and clear limits—not broad security adjectives.

This page describes controls evidenced in the NIYAM product and repository. It does not claim an external certification or guarantee that removes your team’s responsibility for access and sharing decisions.

NIYAM canonical role and permission reference
Curated permission reference. Custom-role creation or external certification is not claimed.
Repository-evidenced controls

Access follows identity, workspace and responsibility.

These statements describe implemented product patterns. Exact access still depends on correct configuration and authorised use.

Authenticated identity

Supported workspace routes require an authenticated user before protected project records are available.

Workspace membership

Access is scoped through workspace membership and the project context available to that user.

Roles and permissions

Supported actions check role or permission requirements instead of relying on a hidden button alone.

Audit events

Supported operational mutations, approvals and administrative actions create traceable events.

Controlled client sharing

Client invitations, portal views and shared reports expose selected workflows rather than the internal workspace.

Production configuration gates

Production startup validates required authentication, storage, AI and other security-sensitive configuration.

Responsible AI boundary

AI prepares information for review. It does not inherit approval authority.

Supported AI workflows can extract fields, organise inputs or raise signals such as a possible duplicate. A responsible person must compare the source, correct errors and decide whether the result is ready for operational use.

AI may prepare
  • Supported document fields
  • Structured drafts from available context
  • Possible duplicate or missing-field signals
People must decide
  • Whether the source is accurate
  • Whether work, rate or evidence is acceptable
  • Whether to approve, pay, share or rely on the result
Client and external access

Share a selected view, not the whole internal workspace.

Client invitations, portal views and supported report links are designed around selected project information. Workspace users remain responsible for recipients, access scope and the records they choose to share.

NIYAM client-safe Project, Reports and Messages view
Curated reference product screen showing the intended client-safe experience.
Security is shared

Controls work only when teams use them deliberately.

Workspace owners and authorised users must manage membership, protect credentials and review sharing choices.

Invite only the intended person
Use the least access needed
Remove access when responsibility changes
Review recipients before sharing
Do not send passwords or OTP codes
Report suspicious access promptly
Report a security concern

Send the affected page or workflow—never a password or OTP.

Describe what you observed and the account or workspace context needed for support. Avoid unnecessary personal or confidential data.

support@niyam.app
Security questions

What this page does—and does not—claim.

Legal notices remain the source for published policy terms.

Does NIYAM claim an external security certification?

No. This page deliberately limits itself to repository-evidenced product and production controls.

Can an administrator control access?

Supported membership, role and permission workflows allow authorised administrators to manage access within the product’s implemented boundaries.

Does NIYAM AI make final approvals?

No. AI output is prepared information or a review signal. Authorised people remain responsible for approval and reliance.

Where are NIYAM’s data-handling terms?

Use the Privacy Policy, AI Data Use Notice and Data Sharing and Subprocessors page in the legal centre.