Trust & AI governance

The AI lives inside the rules.

Most AI tools bolt a chatbot on top of an app. Nahla is the other way around: the data model, the engines, and the permissions came first. The AI sits on top of all three, and cannot reach outside them.

Three layers · one architecture
L3
AI SURFACE
Conversation with visible reasoning
Natural-language chat and agents. Every answer shows a reasoning trace and is grounded in the layers below.
▲ sits on ▲
L2
GOVERNANCE
Engines, permissions, approval gate
Tool allowlist Approval gate Visible reasoning Zero retention
▲ sits on ▲
L1
DATA
Typed model & per-tenant isolation
Tasks · Links · Calendars WBS · Resources · Baselines Encrypted at rest & in transit Authenticated access
⤴ Reads:  .XER  .MPP  .ZIP  plain English

A generic AI bolt-on vs Nahla, by design.

A generic AI bolt-on
Paste full schedule = data leak
Can't read XER / MPP natively
Hallucinates dates & logic
No CPM / DCMA
No approval step
Trains on your data
Nahla, by design
Stays inside your tenant
Reads XER / MPP natively
AI on rule engines, not guesses
DCMA-14 built in
Every change revertible
Zero training by default
The allowlist

What the AI is allowed to do.

The boundary is in code, not in a prompt. The AI has a fixed list of tools, and every call is logged before it commits.

PROPOSES
Drafts a change, you approve
+Add predecessor / successor links
+Fix lags & lead constraints
+Set or update task progress
+Assign resources from your library
+Resource leveling & critical-path plans
READ-ONLY
Computes, never changes
Run CPM / DCMA-14
Monte Carlo risk simulation
S-curves, charts & dashboards
Forecast finish
Trend & baseline comparison
HARD NO
Never, ever
Delete projects or activities
Modify baselines
Change billing or seats
Touch the file system or DB directly
Reach outside its tool allowlist

Agents propose. You approve. Always.

Every agent, including the scheduled ones that run in the background, only proposes. Nothing reaches your schedule, and no email reaches a subcontractor, until you approve it.

Propose-only by design

Chat and background agents draft typed proposals. The only way a change lands in your schedule is your explicit approval, through the same single write path.

No autonomous sends

Progress Collection and Weekly Report draft into your inbox. Emails go out only when you approve them, and only to the recipients you choose, never automatically.

Same guardrails

Agents use the same tool allowlist as the AI rail. Deterministic engines compute every number; baselines stay read-only; every action is logged.

Review & undo

Nothing lands until you approve. Anything can be undone.

Every change the AI proposes waits for your explicit approval on a single write path. Approve it and it applies; change your mind and step back through a 50-step undo history at any time.

Proposed changes · commercial-bldg-2026 · 2 pending AWAITING YOU
set_duration
IM.2.2 Steel Erection · 21d16d
add_link
IM.2.3 → IM.2.4 · FS · lag 2d
level_resources · applied
Foundation Crew · shift May 15‑28 → Jun 3‑7
↶ undo
50-step undo history · Ctrl+Z reverts the AI's last action.
Compliance & infrastructure

Built on the standards enterprise buys.

Hosted on enterprise-grade cloud infrastructure, region-locked, tenant-isolated, encrypted end-to-end. Our AI provider runs under enterprise zero-retention.

Enterprise cloud foundation

ISO 27001 · SOC 1/2/3 · PCI DSS L1 · HIPAA-eligible · FedRAMP. Annually 3rd-party audited.

Encrypted end-to-end

All project data encrypted at rest and in transit. Signed upload URLs on every file.

Enterprise cloud hosting

Region-locked, tenant-isolated, fully managed protected infrastructure.

No AI training by default

Your schedules, costs & resources are never used to train models, unless you opt in.

Zero retention on prompts

Conversations aren't stored, logged, or used for training by our AI provider.

Per-tenant isolation

Strict boundaries between accounts. Every request authenticated and access-checked.

50-step undo history

Ctrl+Z reverts the AI's last action. Every revert is logged too.

Export everything

XER · CSV · PDF export. One click to delete the account, GDPR-aligned.

Your data rights

Your data is yours. Always.

No training. No selling. No reselling. Delete on demand, including your full history.

01 · STRUCTURE
Typed data model

Tasks, links, calendars, resources and baselines all have strict schemas. The AI cannot invent fields. Validation runs before any change is committed, and baselines are read-only to the AI.

02 · GOVERNANCE
Deterministic engines

CPM and DCMA-14 are exact algorithms, not language-model guesses. The AI asks the engines for results, then quotes the numbers verbatim. Same input, same answer, every time.

03 · PRIVACY
Your schedule never leaves your tenant

A generic chatbot needs your whole schedule pasted into a public chat, which becomes someone else's training data. With Nahla it stays inside your isolated workspace. By default nothing trains any model; opt in to help improve Nahla and opt back out any time.

04 · PORTABILITY
Export & delete in one click

Full XER / MPP / CSV / PDF export at any time. One click wipes your projects, history and account. GDPR-aligned.

Want the full security deck?

We'll send you the architecture diagram, cloud shared-responsibility matrix, SOC report letters, and our DPA template.

Request the security pack → Read our DPA