Frequently asked questions
The following questions are among those most frequently raised during enterprise evaluations and operator engagements. For questions not addressed here, contact enterprise@nebbos.ai.
Product
What is Nebbos?
Nebbos is an institutional operations intelligence platform. It comprises four product surfaces — Platform, App, MCP, and Cradle — that together provide operators with a reasoning fabric under their control, backed by an audit chain that satisfies regulatory chain-of-custody requirements without vendor mediation.
Does Nebbos train foundation models?
No. Nebbos orchestrates access to third-party model providers under operator-scoped tier policy. See Responsible AI principle 03.
Does Nebbos use operator data to improve shared models?
No. Operator data remains inside the operator’s scope. Refer to Row-level isolation for the enforcement mechanism.
What is the Cradle?
The Cradle is the hardware root-of-trust for Host-tier and Architect-tier operations. It carries the MCP binary, the operator’s Pearl memory slice, and the cryptographic device key inside a FIPS 140-3 Level 3 secure element. Refer to Cradle provisioning for the enrolment and replacement paths.
Security and compliance
What is Nebbos’s current compliance status?
SOC 2 Type II is in progress. ISO 27001:2022 substrate controls are implemented; the ISMS is in preparation. The EU AI Act Annex IV technical documentation pack is being assembled. GDPR and CCPA data processing addendum is available. See Compliance posture for the complete framework reference.
Is Nebbos HIPAA-compliant?
Nebbos operates in a HIPAA readiness posture. Substrate technical safeguards are implemented; business associate agreements and administrative safeguards are executed per enterprise deployment. Deployments should not be treated as HIPAA-covered until a BAA is in place.
Where does operator data reside?
Team-tier deployments default to us-east-1. Enterprise deployments may specify eu-west-1. Data does not cross regional boundaries absent an explicit, audit-logged replication event. See Subprocessor list for the third parties involved in each region.
How is operator data exported?
Every deployment supports operator-initiated export at any time. The export bundle contains structured data, the audit chain, the knowledge graph, attachments, and a verify.sh script that verifies bundle integrity independently of Nebbos infrastructure. See Portability & export.
Integration
Which SDKs are available?
Python 3.11+ and TypeScript / Node 20+ SDKs are generally available. Go, Rust, Swift, and Kotlin SDKs are on the roadmap. See SDKs & client libraries.
Is an SDK required to integrate?
No. The REST API is fully documented at REST API reference. The OpenAPI specification at OpenAPI supports client generation in any OpenAPI-compatible language.
How are machine-to-machine calls authenticated?
Machine-to-machine authentication uses service accounts. Service accounts have their own tier gate and are provisioned by an Architect-tier administrator. Contact the deployment lead for service account provisioning.
What are the rate limits?
Per-tier sustained rate limits: 10 requests per second at Guest, 60 requests per second at Host, 600 requests per second at Architect. A burst allowance of 4× sustained rate applies for 10-second windows. See Rate limits & quotas.
Pricing and contract
How is Nebbos priced?
Nebbos publishes three tiers — Starter, Team, and Enterprise — at nebbos.ai/pricing . Enterprise pricing is set per deployment based on scope, required tier composition, and integration requirements.
Does every user require a Cradle?
No. Cradles are required for operators at Host-tier and Architect-tier. Guest-tier operators (read operations and low-risk tool calls) do not require a Cradle.
Is a trial deployment available?
Yes. Prospective operators may request a sandbox deployment through their Nebbos contact. Sandbox deployments include Guest-tier identities and a walkthrough of the Cradle ceremony without provisioning production hardware.
Support and incidents
What are the SLA terms?
99.9% monthly uptime at the Team tier and 99.95% monthly uptime at the Enterprise tier. Response-time commitments scale with severity and tier. See SLA for the complete terms and service credit schedule.
How is a security issue reported?
Security reports go to security@nebbos.ai with a one-business-day acknowledgement commitment. See Vulnerability disclosure for the disclosure timeline and scope.
Where is platform status published?
Platform status is published at status.nebbos.ai , including the live board and 90 days of rolling uptime per surface.