Trust & AI governance

The AI lives inside the rules.

Most AI tools bolt a chatbot on top of an app. Nahla is the other way around: the data model, the governance rules, and the permissions came first. The AI sits on top of all three, and cannot reach outside them.

HOSTINGAWS Sydney
ENCRYPTIONAES-256 at rest · TLS 1.3 in transit
YOUR DATANever used to train AI models
CONTROLEvery change waits for your approval
Three layers · one architecture

Rules first. AI on top.

L3AI SURFACE
Conversation, grounded in the layers below

Natural-language chat and agents. Every answer is grounded in the governance rules and data below.

▲ sits on
L2GOVERNANCE
Governance rules, permissions, approval gate
Tool allowlistApproval gateApproval record
▲ sits on
L1DATA
Typed model & per-account separation
Tasks · Links · CalendarsWBS · Resources · BaselinesAuthenticated access
Reads: .XER · .MPP · .ZIP · plain English
By design

A generic AI bolt-on vs Nahla, by design.

A generic AI bolt-onNahla, by design
Your schedulePaste full schedule = data leakStays in your workspace
.XER / .MPPCan't read XER / MPP nativelyReads XER / MPP natively
Dates & logicHallucinates dates & logicAI on governance rules, not guesses
CPM / DCMANo CPM / DCMADCMA-14 built in
ApprovalNo approval step · no record of who approved whatEvery change approved and recorded
The allowlist

What the AI is allowed to do.

The boundary is in code, not in a prompt. The AI has a fixed list of tools. Every agent run, proposal, approval and outbound email is recorded.

PROPOSES

Drafts a change, you approve

  • Add predecessor / successor links
  • Fix lags & lead constraints
  • Set or update task progress
  • Assign resources from your library
  • Resource levelling & critical-path plans
  • Save a new baseline
  • Delete tasks or WBS, only with your approval

READ-ONLY

Computes, never changes

  • Run CPM / DCMA-14
  • Monte Carlo risk simulation
  • S-curves, charts & dashboards
  • Forecast finish
  • Trend & baseline comparison

HARD NO

Never, ever

  • Delete projects
  • Modify baselines
  • Change billing or seats
  • Touch the file system or DB directly
  • Reach outside its tool allowlist
Agents

Agents propose. You approve. Always.

Every agent, including the scheduled ones that run in the background, only proposes. Nothing reaches your schedule, and no email reaches a subcontractor, until you approve it.

Propose-only by design

Chat and background agents draft typed proposals. The only way a change lands in your schedule is your explicit approval, through the same single write path.

No autonomous sends

Progress Collection and Weekly Report draft into your inbox. Emails go out only when you approve them, and only to the recipients you choose, never automatically.

Same guardrails

Agents use the same tool allowlist as the AI rail. Governance rules calculate every number; baselines stay read-only; every agent run and approval is recorded.

Review & undo

Nothing lands until you approve. Anything can be undone.

Every change the AI proposes waits for your explicit approval on a single write path. Approve it and it applies; change your mind and step back with undo in Build, up to 50 steps.

Proposed changes · commercial-bldg-2026 · 2 pendingAWAITING YOU
set_durationIM.2.2 Steel Erection · 21d → 16d
RejectApprove
add_linkIM.2.3 → IM.2.4 · FS · lag 2d
RejectApprove
level_resources · appliedFoundation Crew · shift May 15‑28 → Jun 3‑7
↶ undo

Undo in Build, up to 50 steps · Ctrl+Z reverts the last applied change.

Compliance & infrastructure

Built on the standards enterprise buys.

Hosted on AWS in Sydney and separated by account.

Built on AWS

Hosted in AWS Sydney on fully managed infrastructure that supports GDPR compliance.

Conversations stay yours

Saved in your project so you can pick them up again, and deleted with it.

Separated by account

Strict boundaries between accounts. Every request authenticated and access-checked.

Export everything

P6- and MSP-ready, CSV and PDF export. One click to delete the account.

Your data rights

Your data is yours. Always.

No selling. No reselling. Delete on demand, including your full history.

01 · STRUCTURETyped data model

Tasks, links, calendars, resources and baselines all have strict schemas. The AI cannot invent fields. Validation runs before any change is committed, and baselines are read-only to the AI.

02 · GOVERNANCEGovernance rules

CPM and DCMA-14 are exact algorithms, not language-model guesses. The AI applies the rules for results, then quotes the numbers verbatim. Same input, same answer, every time.

03 · PRIVACYYour schedule stays in your workspace

A generic chatbot needs your whole schedule pasted into a public chat. With Nahla it stays in your isolated workspace, the AI sees only what a question needs, and nothing is used to train AI models.

04 · PORTABILITYExport & delete in one click

P6- and MSP-ready, CSV and PDF export at any time. One click wipes your projects, history and account.

Want our security brief?

We'll send our data-security brief, and a DPA on request.