TermDefinition
AEDTAutomated Employment Decision Tool — used in NYC Local Law 144 and similar US state laws.
AESAdvanced Encryption Standard — symmetric block cipher; AES-256 is Neuroscale’s default for data at rest.
AGPLGNU Affero General Public License — copyleft license with a network-use trigger.
AI Act (EU)Regulation (EU) 2024/1689 — risk-tiered AI regulation; Art. 50 transparency obligations apply to most Neuroscale features.
AMLAnti-Money Laundering — generally out of scope for Neuroscale today.
Argon2idMemory-hard password-hashing function; OWASP-preferred. See Cryptography.
AWSAmazon Web Services — Neuroscale’s primary cloud provider (compute, storage, KMS, secrets, RDS / Aurora, S3, etc.).
BC/DRBusiness Continuity / Disaster Recovery. See the Business Continuity Policy.
BCRsBinding Corporate Rules — intra-group cross-border-transfer mechanism under GDPR. Not currently in scope.
BIPAIllinois Biometric Information Privacy Act (740 ILCS 14).
BISU.S. Bureau of Industry and Security — administers the EAR.
BYODBring Your Own Device — personal devices used to access company resources. See Information Security → Device policy.
CalGINACalifornia’s Genetic Information Nondiscrimination Act extension.
CCPA / CPRACalifornia Consumer Privacy Act, as amended by the California Privacy Rights Act.
CMPCookie Consent Manager / Consent Management Platform (e.g., Cookiebot, OneTrust).
CODE OF CONDUCTNeuroscale’s Code of Conduct policy, owned by the CHRO.
CoD / CODCertificate of Destruction — issued by an approved disposal vendor. See Records Disposal.
Confidential dataHighest classification; see Data Management.
CRA (consumer)Consumer Reporting Agency — Neuroscale’s standard CRA is Checkr. Used in FCRA-compliant background checks.
CRA (EU)EU Cyber Resilience Act (Regulation (EU) 2024/2847) — products with digital elements. Phased compliance through late 2027.
CSA / CSAMChild Sexual Abuse / Child Sexual Abuse Material.
DASTDynamic Application Security Testing.
DDTCU.S. Directorate of Defense Trade Controls — administers ITAR.
DLPData Loss Prevention.
Dodd-Frank §922Whistleblower-protection provision; SEC Rule 21F-17.
DPAData Processing Addendum (with customers); also “Data Protection Authority” in GDPR contexts.
DPFEU-US Data Privacy Framework (and UK Extension, Swiss-US DPF).
DPIA / PIAData Protection Impact Assessment / Privacy Impact Assessment. See DPIA Procedure.
DPOData Protection Officer (GDPR Art. 37). Mandatory appointment is not currently triggered for Neuroscale; the General Counsel acts as voluntary DPO. See DPO independence note.
DSR / DSARData Subject Request / Data Subject Access Request. See Data Subject Rights.
DTSADefend Trade Secrets Act of 2016 (18 U.S.C. §1833(b)) — trade-secret immunity for confidential disclosures to government officials.
EARU.S. Export Administration Regulations (15 C.F.R. Parts 730–774).
EAR99Default ECCN for items not specifically described on the EAR Commerce Control List.
5D002ECCN for “information security” software incorporating non-standard cryptography.
ECCNExport Control Classification Number.
EDREndpoint Detection and Response. Neuroscale uses Rippling.
ENCEAR License Exception ENC — for “mass market” or commercial encryption per 15 C.F.R. §§740.17 and 742.15.
EPA / Equal Pay ActFederal equal-pay statute.
ERNEncryption Registration Number — issued by BIS upon encryption registration.
FCPAU.S. Foreign Corrupt Practices Act (15 U.S.C. §§78dd-1 et seq.).
FCRAU.S. Fair Credit Reporting Act (15 U.S.C. §§1681 et seq.).
FedRAMPU.S. Federal Risk and Authorization Management Program. Future target; not a current commitment.
FDPICSwiss Federal Data Protection and Information Commissioner.
FMLAFamily and Medical Leave Act.
GDPRGeneral Data Protection Regulation (Regulation (EU) 2016/679).
GINAGenetic Information Nondiscrimination Act (42 U.S.C. §2000ff).
GPAIGeneral-Purpose AI model — defined under the EU AI Act Arts. 51–55.
GPCGlobal Privacy Control browser signal.
HashiCorp VaultCross-cloud secrets-of-record for Neuroscale production — static secrets, dynamic secrets, PKI, and Transit-engine application-layer encryption keys. Auth via Vault AWS / Kubernetes / AppRole / OIDC methods. See Secrets Management.
HIPAAHealth Insurance Portability and Accountability Act. Not in scope for Neuroscale — see Data Management → Definitions.
IDTAUK International Data Transfer Agreement (and the related UK Addendum to the EU SCCs).
IdPIdentity Provider. Neuroscale uses Rippling.
IRSU.S. Internal Revenue Service.
IRTIncident Response Team. See Incident Response.
ISMSInformation Security Management System (ISO/IEC 27001:2022 term).
ITARInternational Traffic in Arms Regulations (22 C.F.R. Parts 120–130).
KMSKey Management Service. Neuroscale uses HashiCorp Vault Transit as the application-layer envelope-encryption surface across both clouds (Neuroscale-managed keys, key material never leaves Vault), and AWS KMS for cloud-native at-rest encryption inside AWS-resident services (EBS, RDS / Aurora, S3, DynamoDB). Vultr platform encryption is the equivalent at-rest layer for Vultr-resident services.
LL 144NYC Local Law 144 of 2021 — Automated Employment Decision Tools.
MAMMobile Application Management. Used for BYOD mobile devices via Rippling.
MDMMobile Device Management. Used for company-owned devices via Rippling.
MFAMulti-Factor Authentication.
MNPIMaterial Non-Public Information. See Insider Trading.
MPLMozilla Public License.
NIS2EU Network and Information Security Directive 2 (Directive (EU) 2022/2555) — 24h early-warning / 72h notification for “essential” and “important” entities. Not currently in scope.
NISTU.S. National Institute of Standards and Technology.
NLRANational Labor Relations Act (29 U.S.C. §§151 et seq.); §7 protects concerted activity.
NLRBU.S. National Labor Relations Board.
OFACU.S. Office of Foreign Assets Control — administers economic sanctions.
OSHAU.S. Occupational Safety and Health Administration; §11(c) prohibits retaliation.
OWASPOpen Web Application Security Project.
PBKDF2Password-Based Key Derivation Function 2 — acceptable password-hashing where Argon2id is unavailable.
PIIPersonally Identifiable Information. See Data Management → Definitions for the full umbrella definition.
RBACRole-Based Access Control.
ROPARecords of Processing Activities (GDPR Art. 30).
RTO / RPORecovery Time Objective / Recovery Point Objective. See RTO/RPO Matrix.
SASTStatic Application Security Testing.
SBOMSoftware Bill of Materials. See Open Source & SBOM Policy.
SCASoftware Composition Analysis (dependency scanning).
SCCStandard Contractual Clauses (EU Commission Implementing Decision (EU) 2021/914).
SDNSpecially Designated Nationals (OFAC list).
SEDSelf-Encrypting Drive.
SLAService Level Agreement.
SOC 2Service Organization Control 2 — the audit framework Neuroscale follows.
SOXSarbanes-Oxley Act of 2002. §806 (18 U.S.C. §1514A) is the civil whistleblower provision; §1107 (18 U.S.C. §1513(e)) is the criminal anti-retaliation provision.
SPISensitive Personal Information (CPRA §1798.121).
SSOSingle Sign-On. Neuroscale uses Rippling.
TATThreat Assessment Team. See Workplace Violence Prevention.
TIATransfer Impact Assessment. See TIA Template.
UKBAUK Bribery Act 2010.
USERRAUniformed Services Employment and Reemployment Rights Act.
VultrConstant Company, LLC, dba Vultr — Neuroscale’s secondary cloud provider for compute and database hosting. Hosts Vultr Cloud Compute, Vultr Bare Metal, Vultr Object Storage, Vultr Block Storage, and Vultr Kubernetes Engine (VKE).
VKEVultr Kubernetes Engine — managed Kubernetes on Vultr.
VPCVirtual Private Cloud.
WARPCloudflare’s VPN/tunnel client (part of Cloudflare One).
WORMWrite-Once Read-Many storage (e.g., S3 Object Lock).
WVPPWorkplace Violence Prevention Plan (Cal. Lab. Code §6401.9 / SB 553).

Version history

VersionDateDescriptionAuthorApproved by
1.0May 8, 2026Initial versionCameron WolfeIshan Jadhwani
1.1May 9, 2026Expanded ~70 entries to cover the post-audit doc set (MNPI, NIS2, FCRA, FCPA/UKBA, DTSA, NLRA, EAR/OFAC/BIS family, ITAR, AEDT, SPI, ROPA, TIA, DPF/SCC/IDTA, WVPP, GPAI, CMP, SBOM, Argon2id, etc.).Cameron WolfeIshan Jadhwani