Most AI tools bolt a chatbot on top of an app. Nahla is the other way around: the data model, the engines, and the permissions came first. The AI sits on top of all three, and cannot reach outside them.
The boundary is in code, not in a prompt. The AI has a fixed list of tools, and every call is logged before it commits.
Every agent, including the scheduled ones that run in the background, only proposes. Nothing reaches your schedule, and no email reaches a subcontractor, until you approve it.
Chat and background agents draft typed proposals. The only way a change lands in your schedule is your explicit approval, through the same single write path.
Progress Collection and Weekly Report draft into your inbox. Emails go out only when you approve them, and only to the recipients you choose, never automatically.
Agents use the same tool allowlist as the AI rail. Deterministic engines compute every number; baselines stay read-only; every action is logged.
Every change the AI proposes waits for your explicit approval on a single write path. Approve it and it applies; change your mind and step back through a 50-step undo history at any time.
Hosted on enterprise-grade cloud infrastructure, region-locked, tenant-isolated, encrypted end-to-end. Our AI provider runs under enterprise zero-retention.
ISO 27001 · SOC 1/2/3 · PCI DSS L1 · HIPAA-eligible · FedRAMP. Annually 3rd-party audited.
All project data encrypted at rest and in transit. Signed upload URLs on every file.
Region-locked, tenant-isolated, fully managed protected infrastructure.
Your schedules, costs & resources are never used to train models, unless you opt in.
Conversations aren't stored, logged, or used for training by our AI provider.
Strict boundaries between accounts. Every request authenticated and access-checked.
Ctrl+Z reverts the AI's last action. Every revert is logged too.
XER · CSV · PDF export. One click to delete the account, GDPR-aligned.
No training. No selling. No reselling. Delete on demand, including your full history.
Tasks, links, calendars, resources and baselines all have strict schemas. The AI cannot invent fields. Validation runs before any change is committed, and baselines are read-only to the AI.
CPM and DCMA-14 are exact algorithms, not language-model guesses. The AI asks the engines for results, then quotes the numbers verbatim. Same input, same answer, every time.
A generic chatbot needs your whole schedule pasted into a public chat, which becomes someone else's training data. With Nahla it stays inside your isolated workspace. By default nothing trains any model; opt in to help improve Nahla and opt back out any time.
Full XER / MPP / CSV / PDF export at any time. One click wipes your projects, history and account. GDPR-aligned.
We'll send you the architecture diagram, cloud shared-responsibility matrix, SOC report letters, and our DPA template.