New NN AI is here — governed agentic intelligence across the systems you already run on NEHANET CRM. Explore NN AI →
Platform

Choose your deployment. Keep responsibility and access boundaries clear.

Permissions are part of the operating model, not an afterthought. Whether NEHANET runs hosted or on your own infrastructure, access is governed by company, role, region, and record scope from day one.

Deployment models

Hosted, or on your own infrastructure.

Hosted / Cloud

NEHANET-managed application hosting with browser-based access. No customer server installation is required — NEHANET and its infrastructure partners operate the application, and integration patterns are selected around your network boundaries.

On-Premises

Customer-operated infrastructure with NEHANET application installation. You provide a Windows server-class machine and Microsoft SQL Server; NEHANET installs Tomcat, Java, and the application. Remote installation and support access are governed by your policy.

Access governance

Permissions are part of the operating model.

Four layers of control apply across every deployment, hosted or on-premises.

  • Identity and authentication

    Account lifecycle, authentication method, session policy, single sign-on, and administrative controls.

  • Organization and role

    Users are associated with company, role, region, business unit, team, and partner relationship.

  • Module, action, and record scope

    Which applications a user can open, which operations they can perform, and which records they can see.

  • Review and audit

    Provisioning, modification, suspension, periodic access review, logging, and evidence retention.

Security review

What a security review with NEHANET covers.

Current infrastructure, encryption, retention, backup, incident-response, subprocessor, and certification detail is provided through a security review scoped to your deployment — not published as a generic claim.

Architecture & tenancy

Hosting locations, logical isolation, network boundaries, application separation, and environments.

Encryption & key management

Transport and storage encryption, certificate ownership, key custody, and rotation.

Backups & recovery

Frequency, retention, location, restore testing, recovery point and time objectives.

Operations & incident response

Monitoring, vulnerability management, patching, logging, notification, and escalation.

Compliance & assurance

Current provider reports, certifications, penetration testing, and contract documentation.

Subprocessors & data lifecycle

Approved vendors, purpose, geography, retention, deletion, and termination handling.

On-premises responsibility checklist

What we confirm together before go-live.

1

Infrastructure

Customer-approved Windows server, SQL Server, storage, network, and environment prerequisites.

2

Application components

Supported Java, Tomcat, application, database, and browser versions, confirmed by engineering.

3

Remote access

Approved installation and support method, authorization, logging, time limits, and revocation.

4

Email

SMTP relay, authentication, allowed senders, and alert behavior.

5

Backup and recovery

Customer backup, offsite retention, restore testing, and disaster-recovery ownership.

6

Patching and perimeter

Operating system, SQL, firewall, endpoint, and change-management responsibilities.

Customer proof

Deployment shouldn't be a burden on your IT team.

“Cloud deployment reduced the burden on our limited internal IT resources.”
DV
David VillanuevaDirector of IT · Cortina Systems
2
deployment models — cloud or on-premises
4
layers of access governance
6
point on-premises responsibility checklist

Complete a deployment and security review before commercial scope is finalized.

The review produces a responsibility matrix, current requirements, a data-flow diagram, an access model, integration controls, a backup and recovery plan, and the trust documentation your team needs.