Trust
Nuronus is a TypeScript application (Next.js, Node API, PostgreSQL) with real integrations and a mapped control library. AI is used in two places, on purpose. It does not invent HIPAA scores.
Copilot can draft policy language, remediation notes, and a short narrative from assessment data already in your tenant (scores, open gaps, client name). Predictive-risk copy uses the same class of model. Those drafts do not change client environments, do not run remediations, and are not an auditor opinion.
Control readiness is computed from mapped CIS controls and check status, not from the model. You can ignore Copilot and still run assessments, mappings, and reports.
Engineering uses AI coding tools the way most software teams do now. The product is not a no-code app generated end-to-end. Auth, multi-tenancy, RMM/PSA connectors, and the control catalog are conventional code with automated tests.
When Copilot is used, the prompt includes the user's question plus assessment context (for example security score, top risks, framework readiness). That request goes to Anthropic's API. We do not use customer data to train Nuronus models. Anthropic's commercial API is not used by Nuronus to train a Nuronus-owned model.
If you do not want assessment context sent to a model, do not use Copilot. Core scoring, evidence, and PDF reports still work.
Sample PDFs are labeled demo data. Tables and statuses are from mapped controls. Any prose block is a client-facing summary, not the scoring engine. Open the sample report · Security