IT Translation Pack v2 (CISO Edition)
REDLINE deployment is not a multi-tenant cloud. The standard 300-question SaaS security questionnaire mostly does not apply. This packet is the substitute: topology diagram, in-transit cipher spec, mTLS / SAML / SSO support matrix, DLP and EDR allowlist template letters, cross-border compliance matrix. Hand it to the firm's CISO. Hand it to the carrier. Hand it to outside counsel. The audit clears in one meeting.
The firm-side requirement is one outbound HTTPS connection from authorized workstations to legal.nohumannearby.com. No inbound port. No firm-side appliance. No third-party AI vendors or cloud middlemen in the inference chain.
Every byte between the firm workstation and the dedicated NHN-operated inference capacity is wrapped in TLS 1.3 with mutual authentication. The cipher suite is pinned, no downgrade, no opportunistic encryption.
| Layer | Spec |
|---|---|
| Protocol | TLS 1.3 (RFC 8446) only. TLS 1.2 and earlier are rejected at the edge. |
| AEAD Cipher | TLS_AES_256_GCM_SHA384 (preferred), TLS_CHACHA20_POLY1305_SHA256 (fallback) |
| Key Exchange | X25519 (Curve25519). Post-quantum hybrid X25519+Kyber768 in pilot on a customer-elected basis. |
| Authentication | Mutual TLS. NHN pins the customer-issued client certificate fingerprint at provisioning. Customer pins the NHN-issued server certificate fingerprint at SSO setup. |
| Certificate Authority | Customer's PKI for the client cert chain. NHN's PKI for the server cert chain. Cross-pinned at the edge. |
| Certificate Lifetime | Client certs rotated annually. Server certs rotated quarterly. ACME automation on both sides. |
| Forward Secrecy | Enforced. Every session uses a fresh ephemeral key exchange. |
| Session Resumption | PSK with at most 24-hour ticket lifetime. 0-RTT is disabled. |
Authentication flows through the firm's existing identity provider. NHN does not maintain a user store on the firm's behalf.
| Identity Provider | SAML 2.0 | OIDC | SCIM | MFA Pass-Through | Config Link |
|---|---|---|---|---|---|
| Okta | Yes | Yes | Yes | Yes | Setup guide on request |
| Azure AD / Entra ID | Yes | Yes | Yes | Yes (Conditional Access pass-through) | Setup guide on request |
| Google Workspace | Yes | Yes | Yes | Yes | Setup guide on request |
| Ping Identity | Yes | Yes | Yes | Yes | Setup guide on request |
| Generic SAML 2.0 | Yes | via OIDC bridge | via SCIM bridge | Pass-through to IdP | Generic SAML config template |
| On-Prem ADFS | Yes | via OIDC bridge | via SCIM bridge | Pass-through | ADFS federation setup guide |
For firms with strict outbound DLP and endpoint EDR controls, the legal.nohumannearby.com edge needs to be allowlisted at three places: the firm's outbound web proxy, the firm's EDR endpoint policy, and the firm's DLP egress inspector. The following template letter is the firm CISO's pre-filled artifact.
Regional NHN-controlled compute nodes service jurisdictionally-scoped deal rooms. Routing is pinned at the residency intake form signed by the firm's privacy counsel before any document is ingested.
| Region | Residency Posture | Trustee Jurisdiction (SDMS) | SLA |
|---|---|---|---|
| US-East / US-West | US-domiciled processing only. No cross-border egress. | Customer-elected trustee in US jurisdiction (default) | Live, 99.95% uptime SLA |
| EU-Frankfurt / EU-Amsterdam | EU-only processing. GDPR Article 44-50 compliant via local-entity ring-fence. Co-location provider has zero logical access. | Customer-elected EU-domiciled trustee (default for EU firms) | Available on enterprise contract |
| UK-London | UK-only processing. Post-Brexit data residency clean. | Customer-elected UK-domiciled trustee | Available on enterprise contract |
| APAC-Singapore / APAC-Tokyo | APAC-only processing. PDPA / APPI compliance via local-entity ring-fence. | Customer-elected APAC-domiciled trustee | On request, Q4 2026 target |
SDMS trustee model. The Sovereign Deadman Switch uses customer-elected trustees in different legal jurisdictions for threshold-key release, replacing the traditional third-party escrow-vendor model. Trustees hold key shares only; they do not host or operate any NHN infrastructure. Customer counsel selects the trustee roster at contract signing.
Full per-region playbook (including the residency intake form, the per-region audit-log schema, and the customer-counsel review materials) is in the Procurement Audit Pack.
For the full procurement audit pack (named co-location facility roster, SOC 2 Type 2 reports under NDA, the residency intake form, the cipher rotation schedule, and the customer-side IOA suppression / DLP exception XML in editable form):
Email: legal@nohumannearby.com