Skip to content
NiuCore

Trust

Transparency about how your data is handled

NiuCore uses AI models from external providers. Instead of claiming that information never leaves the platform, this page sets out what is sent, in what form, and what remains under NiuCore's control.

The path of a message

  1. The employee writes

    The message reaches NiuCore over an encrypted connection.

  2. Permission check

    The area, libraries, connectors and models enabled for that person.

  3. Anonymization

    The three layers replace sensitive data with placeholders. The link between placeholder and data stays in NiuCore.

  4. Processing

    The model receives the text with placeholders and returns its response.

  5. Restoration

    NiuCore restores the data and the employee receives the complete response.

  6. Record

    Consumption traceability is kept: user, date, model and niucredits.

What information is kept, and where

What information is kept, and where
InformationLocationNote
Conversations and configurationNiuCore's infrastructure on Amazon Web Services and Microsoft Azure, providers certified under ISO/IEC 27001Isolated by company. Information is encrypted at rest and in transit
Documents uploaded to a libraryThe original file is not kept: it is processed and deleted. NiuCore keeps the text extracted from the document in its storage on AWS, within its own infrastructureThat text is not sent to model providers: the search index and everything the model receives carry sensitive data already replaced. Accessible according to the area's permissions
Document search indexNiuCore's vector databaseWith anonymization active, the text is indexed already replaced
Dictionary and placeholder–data linkNiuCore's infrastructureNot sent to the model provider
Files in Drive, OneDrive and other connectorsIn the company's account with the original serviceFrom the conversation, NiuCore accesses the original document directly, with each user's authorization, and does not copy it. Only if the document is added to a library is its content indexed
Payment dataMercado PagoNiuCore does not receive the card number

AI providers and the organization's control

NiuCore provides access to models from OpenAI, Anthropic, Google, xAI, DeepSeek, Alibaba (Qwen), Moonshot, Zhipu and ByteDance. All of them receive the same treatment: text with placeholders instead of sensitive data.

Full catalog by default, which the organization can narrow

Profesional Standar and Profesional MAX licenses give access to every model. If company policy requires it, each area can be restricted to approved providers; a private area can operate exclusively with them.

The same protection for every provider

Anonymization happens before the provider is selected. No provider receives unreplaced data.

The platform's internal tasks

Besides the model that answers, NiuCore uses models to select the model in Auto mode, summarize long conversations and generate next best action recommendations. These tasks follow the same anonymization flow and run on the best available model among those enabled in the user's area; they therefore respect each area's provider restrictions. Library indexing uses OpenAI models and receives text that is already anonymized.

Provider unavailability

In Auto mode, NiuCore switches to another of the models enabled in the area so work can continue. With a fixed model, it reports that the model is unavailable instead of replacing it.

Model training

NiuCore does not train its own models with its clients' information. It accesses third-party models through their enterprise services or their application programming interfaces, not through their free or consumer versions, and contracts under terms that exclude the use of information for model training with every provider whose standard API terms provide for it. The table below states each provider's position; if your organization's policy requires it, areas can be restricted to the providers that exclude it.

Protection that does not rest on third-party promises

NiuCore contracts with each provider, wherever its standard API terms provide for it, under terms that exclude the use of information for model training or for any other unauthorized purpose. Even so, neither NiuCore nor your organization can verify from the outside that a third party keeps its promises. That is why active anonymization is the core of the platform: replacement happens inside NiuCore, before anything is sent. Names, identity documents, contact details, contracts and your organization's own terms travel as placeholders —⟦Person#7F3A2C⟧, ⟦Document#B81E44⟧, ⟦Contract#4E91D0⟧— and the mapping between each placeholder and the real data stays within NiuCore: no provider receives it. A provider that retains the text it receives, or uses it to improve its models, retains placeholders, not your organization's data.

Terms of each model provider

All of them receive text with placeholders instead of sensitive data. This table also sets out what each provider's terms say about the information it receives.

Terms of each model provider
ProviderUse of information for model trainingWhere it is processedRetention by the provider
OpenAIExcluded under its API termsUnited StatesUp to 30 days, for abuse detection
AnthropicExcluded by contractUnited StatesAs set out in its commercial terms
GoogleExcluded in the paid service NiuCore usesCountries where Google maintains facilitiesA limited period, for abuse detection
xAIExcluded unless expressly authorizedThe provider's global infrastructure30 days, for abuse detection
Alibaba (Qwen)ExcludedSingaporeNo period published
ZhipuExcluded unless expressly agreedSingaporeThe provider states that it does not store content
ByteDanceExcluded unless expressly authorizedMalaysia, Indonesia or Europe (EU/EEA)Content that triggers its safety filter is retained for 180 days, in Malaysia
MoonshotThe provider reserves the right to use information to improve its servicesSingaporeNo period published
DeepSeekIts terms do not exclude itChinaNo period published

Information taken from each provider's public terms, reviewed in [MONTH AND YEAR OF PUBLICATION]. NiuCore updates this table when a provider changes its terms.

Anonymization: scope and limits

Scope

Employees' messages and conversation history, library documents, attachments, images and scanned documents, information delivered by connectors, and next best action recommendations.

Reversible by design

Placeholders are restored so the employee receives the response with the real data.

It is not infallible

No detector recognizes every piece of sensitive data.

It applies to what is processed in NiuCore

It does not intercept other applications.

Access control

Isolation between companies

Each company's information is kept separate. No content—including what a company marks as public—is visible to another.

Permissions by area and by role

Each user accesses only the libraries, connectors and models of their areas. Permissions are defined by capabilities, not by job titles.

Oversight by the company

Company administrators with the corresponding permission can view their users' conversations and contexts, including those the user keeps private from colleagues. No other company has access to them.

Two-step verification

Available for user accounts and enforceable by the company.

Per-action permissions on connectors

The company defines which actions it authorizes on each connector: for example, allowing emails to be read but not sent.

Area memory

Operational memory belongs to each area, is not combined with that of others, and is stored with sensitive data already replaced. Each user sees only their own recommendations, and the administrator can delete an area's memory.

Operational continuity

Designed to keep work going

If an AI provider becomes unavailable, and in Auto mode, NiuCore switches to an alternative model. If a conversation is interrupted, the platform reconciles it and keeps what was generated. The Terms and Conditions set out a 99% monthly availability commitment, its calculation formula and the advance notice for maintenance windows.

Frequently asked questions

Can the company's data reach a provider based in China?

By default, users can choose any model in the catalog, including those from providers based in China, and in every case the text is sent anonymized: the provider receives placeholders, not the company's data. The table of provider terms on this page shows where each provider processes information. If company policy does not allow it, areas can be restricted to approved providers, and those models are no longer available to their users.

Why not use a private AI, with in-house models and data that never leaves the company?

It is a valid alternative when isolation is the absolute priority. The trade-off is capability: the models an organization can host on its own are today noticeably inferior to those of the leading labs, and they require dedicated infrastructure and maintenance. NiuCore starts from the opposite criterion: use the most capable models available and protect the information by replacing sensitive data before sending it.

Does NiuCore use the company's data to train models?

NiuCore does not train models. Area memory and the dictionary improve the service for the company itself; they do not modify any model and are not shared with other companies.

Can NiuCore staff access the company's information?

Access by NiuCore staff is restricted through role- and profile-based controls and confidentiality agreements, and is limited to what is necessary to provide the service and support, in accordance with the Privacy Policy.

Can NiuCore be installed on the company's own infrastructure?

No. NiuCore is currently offered exclusively as a cloud service, operated by NiuCore.

What happens to the data if the company cancels the service?

NiuCore deletes the hosted information three months after the effective termination of the contractual relationship. Anonymized usage records may be kept for statistical and product improvement purposes. The company may request earlier deletion by writing to privacy@niucore.com.

Technical information for IT and legal teams

The documentation describes how the platform and active anonymization work, with the level of detail a formal evaluation requires.

Inquiries from IT and legal teams are answered in writing through Contact.