Industry Leadership
Strategic Initiatives
CSA's strategic programs driving innovation in AI, cloud, and Zero Trust.
A public-interest 501(c)(3) dedicated to secure and trustworthy AI.




Industry Leadership
Strategic Initiatives
CSA's strategic programs driving innovation in AI, cloud, and Zero Trust.
A public-interest 501(c)(3) dedicated to secure and trustworthy AI.

CSAI FoundationChaptersEventsBlog
Prepare for machine-speed cybersecurity with CSA Corporate Membership + Frontier Ready Support for $9,000. Offer ends September 30 →

CSA STAR Registry

Security, Trust, Assurance, and Risk Registry

Listings for Nadir

Listings for Nadir

Nadir is an LLM routing service from Nadir Tech LLC. Customers send OpenAI- or Anthropic-compatible API requests to api.getnadir.com. Nadir picks a model for each request and forwards it to the provider (Anthropic, OpenAI, Google or AWS Bedrock), using the customer's own provider key or Nadir's. The dashboard at app.getnadir.com manages keys, settings and usage.

Scope: the hosted Nadir service. The API runs on AWS App Runner (us-east-1), the database and authentication on Supabase (us-west-2), and the website and dashboard on Cloudflare. Customer data is stored in the United States.

Security highlights - TLS on every endpoint and encryption at rest; customer provider keys are also encrypted at the application layer - API keys stored only as SHA-256 hashes; tenant isolation in the application and with Row Level Security - Customers can turn prompt storage off (a hash is kept instead) and delete their account and data from Settings - AWS CloudTrail audit logging, security alerting and daily database backups - Subprocessors published in the Privacy Policy; a DPA is available

This is a CSA STAR Level 1 self-assessment, not a third-party audit. Security contact: info@getnadir.com

Nadir

Nadir Tech LLC builds Nadir, an LLM routing service. Nadir sends each AI request to a model suited to the task and forwards it to the pro...

Listed Since: 2026-09-27

CAIQ
Offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services. It provides a set of Yes/No/NA questions and space to justify the response a cloud consumer and cloud auditor may wish to ask of a cloud provider to ascertain their compliance to the Cloud Controls Matrix (CCM).