Nanonets
Nanonets runs AI agents that read business documents — invoices, purchase orders, bills of lading — then validate, match and post the results directly into SAP, Salesforce or any ERP. Billed per block executed, with enterprise-grade deployment options.
What is Nanonets?
Nanonets is an enterprise platform that turns written operating procedures into working AI agents. Its pitch is blunt: your SOPs become agents. The company captures the surrounding context, your team sets the direction, and the agents do the work inside the tools already in place. Behind them sits what Nanonets calls a context graph — a machine-readable map linking documents, systems of record, computed values and business rules, so that a question like "this French distributor is ninety days overdue, what do we do?" can be answered from five systems at once rather than one. The company claims 94% of complex, document-heavy processes can be automated, leaving 6% to human judgement.
The platform ships as a set of composable blocks. Agent Builder lets you describe a step in plain language instead of dragging boxes. Document Intelligence reads any document without templates. Document Generation writes results back out as CSV, XLSX, PDF, DOCX, HTML or Markdown. Exception Management routes what the agent cannot settle to the right reviewer with full context, then picks the work back up. Analytics answers plain-English questions about the workflow, and Agent Collaboration connects SAP Joule, Salesforce Agentforce and Microsoft Copilot into one chain.
The extraction engine is the company's own model, Nanonets OCR-3, which it reports at 85.9 on the public IDP Leaderboard against 83.5 for GPT-5.4 and 82.8 for Gemini 3 Pro. Smaller open models are published on Hugging Face under Apache-2.0. Recognition covers 226 named languages, mixed-script pages and handwriting. Developers reach the same capability through parse, extract, split and chunk APIs returning clean markdown plus structured JSON.
The enterprise side is unusually complete for a tool of this size: SAML and OIDC single sign-on, SCIM provisioning, role-based access, audit logs streamed to a SIEM, AES-256 encryption at rest and TLS 1.3 in transit, bring-your-own-keys, and deployment in a VPC, a single-tenant cloud or on-premise. Named customers include Schneider Electric, Mondelez, Roche and UniPro, the latter reporting 93% touchless order processing.
What it does
- Extract structured data from invoices, purchase orders, bills of lading, contracts and bank statements
- Match an invoice against its purchase order and flag discrepancies in quantities, prices or line items
- Post validated data straight into SAP, Salesforce, an ERP or a database
- Run accounts payable, order processing and shipment reconciliation end to end
- Route uncertain cases to a human reviewer in Slack, Teams or email, then resume automatically
- Process reimbursement claims and loan files from unstructured paperwork
- Generate finished documents in CSV, XLSX, PDF, DOCX, HTML or Markdown from structured data
When to use Nanonets / When not to
A quick filter to help you decide if Nanonets is the right fit.
When to use Nanonets
- Accounts payable teams drowning in supplier invoices and manual GL coding
- Order management and logistics operations reconciling purchase orders, shipments and bills of lading
- Insurance claims handlers and healthcare billing teams working from unstructured paperwork
- Data and platform engineers who need a document-extraction API to feed RAG or agent pipelines
- Large organisations requiring SSO, role-based access, audit logging and private or on-premise deployment
When not to use Nanonets
- Individuals and micro-businesses: the entry commitment is USD 100 per month once the opening credits are spent
- Occasional users with a handful of documents to process each month
- Anyone expecting a mobile app — Nanonets ships neither an iOS nor an Android application
- Buyers who need a contractual guarantee that no derived data is reused, which clause 6.3 of the terms does not give outside Google and Microsoft APIs
- Teams that must keep data outside the United States but have no Enterprise budget
How to use Nanonets
A typical end-to-end flow, from setup to results.
- Open an account at the signup page — no credit card is required and USD 50 of credits are granted immediately
- Upload your existing runbooks and standard operating procedures so the agent learns the business intent behind the task
- Describe the workflow step by step in plain language in Agent Builder, adding tools where each step needs them
- Connect your document sources once: Gmail, Outlook, Google Drive, Dropbox, Box, Notion, OneDrive, SharePoint or a direct API drop
- Let the agent extract and validate the data against your rules, with no per-format template to configure
- Set the approval gates: low-confidence items and high-value transactions route to a named reviewer
- Connect the destination system — SAP, Oracle, NetSuite, Dynamics 365, QuickBooks, Xero, Sage, Salesforce, HubSpot — or a webhook for anything else
- Run a first task from the live sandbox, for example matching an invoice against a purchase order, before committing volume
- Correct the agent where it errs: every correction updates its instructions without a retraining cycle
- Track throughput, automation rate and AI cost from the dashboards, or ask the analytics layer a question in plain English
Pros & Cons
Pros
- Extraction quality is backed by a public third-party ranking rather than a self-declared benchmark, with the in-house model placed ahead of general-purpose frontier models
- The security posture is documented in depth: SOC 2 Type I and II, ISO/IEC 27001, HIPAA with a BAA on enterprise plans, and bi-annual third-party audits
- A named subprocessor list is published and a DPA can be reviewed and signed online — rare transparency at this level of detail
- Pricing for the entry tier is genuinely public, down to the unit price of each block type, with no platform fee and no seat licence
- USD 50 of credits are granted without a card and carry no expiry date
- Heavy deployment options are available: private VPC, single-tenant cloud or on-premise, with data residency in the US, EU or APAC
- Public API documentation, prebuilt models for common document types and open models released on Hugging Face
Cons
- There is no permanent free tier: once the opening credits are spent, the real entry point is USD 100 per month
- Growth and Enterprise carry no published price at all — both are quote-only
- The final bill is hard to forecast because it depends on how many blocks each document consumes, four to six for a typical invoice
- The marketing promise of a zero training guarantee sits awkwardly beside clause 6.3 of the terms, which lets Nanonets freely use Derived Data to improve its products
- The legal corpus is uneven in age: terms, security policy and subprocessor list date from 2020-2021 while the privacy notice was rewritten in July 2026
- SOC 2 and ISO 27001 reports are not publicly viewable — they are released only under NDA
- No mobile application, no dedicated about or contact page, and the homepage demo buttons pointed nowhere on the day of review
Pricing & Plans
There is no permanent free plan. Every new account opens with USD 50 of credits, granted without a payment card and carrying no expiry date — an allowance the vendor itself describes as the free trial. Beyond it, the lowest recurring commitment is USD 100 per month for 100 credits on the Starter tier. Actual consumption is metered per block executed: USD 0.02 for a simple operation such as formatting, routing or export, USD 0.10 for a standard AI block such as classification or validation, and USD 0.30 for a complex block such as extraction or generative AI. A typical invoice workflow runs four to six blocks per document. The Growth and Enterprise tiers are priced on request, with volume discounts reaching 40%.
- data extraction AI
- API access
- email integration
- cloud storage connectors
- up to 3 users
- community support
- everything in Starter plus classification AI
- barcode and signature detection
- generative AI blocks
- custom Python blocks
- ERP and database integrations
- custom integrations
- AI reporting and analytics
- team-wide credit sharing and up to 40% volume discount
- everything in Growth plus SAML SSO and SCIM
- role-based access control
- HIPAA and SOC 2 compliance
- private cloud or on-premise deployment
- data residency in the US
- EU or APAC
- Salesforce
- SAP and Oracle connectors
Data, GDPR & hosting
A consolidated view of how Nanonets handles your data.
GDPR overview
GDPR compliance is claimed explicitly rather than merely implied: a dedicated page states that Nanonets complies with the regulation and helps its customers do the same. A Data Protection Officer is appointed and reachable at dpo@nanonets.com, by phone, or by post at the San Francisco office. Transfers rest on certification to the EU-U.S. Data Privacy Framework, its UK extension and the Swiss-U.S. framework, under Federal Trade Commission oversight. A Data Processing Agreement can be reviewed and signed online, with Nanonets acting as processor. Permanent deletion can be requested and is answered within thirty days. Two gaps remain worth knowing: no Article 27 representative is designated in the European Union, and the dedicated GDPR page carries a five-year-old update stamp while the privacy notice was rewritten in July 2026.
Who owns the data?
The terms of service are explicit: Customer Data is, and remains, the property of the customer. The customer grants Nanonets a non-exclusive, non-transferable, non-sub-licensable, worldwide and royalty-free licence to use, collect, transfer and process that data for the sole purpose of delivering the service. A separate clause carves out Derived Data — anything Nanonets generates from customer content — which the vendor may freely use for its internal business purposes, including improving, testing, operating, promoting and marketing its own products. Only Derived Data originating from Google Workspace or Microsoft APIs is contractually excluded from developing or training generalised AI models. Under the GDPR, Nanonets acts as processor and the customer as controller.
Reuse rights
Customers keep full rights over what they upload and over the structured output the agents produce: nothing in the terms restricts reusing extracted data, exporting it or writing it into third-party systems, which is precisely the intended workflow. Access to connected accounts is scoped to what the user configures — specific Gmail labels, selected Drive folders — and happens only on a user action or a trigger they set up. The product pages advertise a zero training guarantee, and the July 2026 privacy notice confirms that Google user data is excluded from every training, fine-tuning, evaluation and benchmarking dataset, and never used to improve behaviour for another tenant; third-party model providers act as subprocessors and are barred from retaining that data or training on it. Where a customer asks Nanonets to refine an extraction model, that model stays inside their own tenant and can be deleted at any time. The Derived Data clause in the terms is broader than the marketing promise, so the two documents do not fully align.
Data retention & training
Hosting summary
The security policy is unambiguous on the default: all customer data is stored in the USA, on Amazon Web Services and Google Cloud facilities, inside a virtual private cloud protected by network access control lists. Nanonets runs no routers, load balancers, DNS or physical servers of its own. Data sits in multi-tenant datastores with logical separation enforced in application code and covered by automated tests, and a backup solution protects the datastores holding customer content. Encryption is AES-256 at rest and TLS at 256 bits in transit, with an A+ SSL Labs rating claimed. The declared infrastructure subprocessors — Amazon Web Services, Google Cloud, Microsoft Azure, SendGrid, Auth0 and Imgix — are all US entities, as are the support-side ones, Zendesk, Intercom, Google Workspace, HubSpot and Airtable. Regional residency in the US, EU or APAC exists, along with VPC, single-tenant and on-premise deployment where the customer keeps its own keys and network policies, but these are Enterprise-tier options rather than the standard configuration.
Things to keep in mind
Risks and trade-offs to weigh before adopting Nanonets.
- The zero training guarantee shown on the product pages is not mirrored in the terms of service, whose Derived Data clause lets Nanonets freely use data generated from your content to improve and market its products, with an explicit training exclusion only for Google and Microsoft API sources
- Agents post decisions into systems of record with no human in the middle by default: a silent extraction error does not stop at the screen, it propagates into the ledger, the ERP and downstream reporting
- Automating 94% of a process erodes the team's familiarity with the remaining 6%, which is precisely the hardest part — the exceptions nobody has practised handling for a year
- Trusting a benchmark position as a proxy for accuracy on your own documents is risky: leaderboard scores are measured on public corpora, not on your vendor layouts, and the site itself concedes low-confidence cases exist
- SOC 2 and ISO 27001 certificates cannot be inspected before signing an NDA, so the compliance claim has to be taken on trust during evaluation
- The security policy states all customer data is stored in the USA while the commercial pages advertise EU and APAC residency: the option exists but is gated behind the Enterprise tier, and assuming otherwise could breach an internal data policy
- Usage-based billing makes cost a function of workflow design: a badly composed agent that runs extra blocks per document raises the bill without anyone noticing until the invoice arrives
Setup & Integrations
Technical difficulty
Entry is deliberately frictionless: an online account, USD 50 of credits, no card. Building an agent means describing steps in plain language and uploading existing SOPs, with no template to configure and a single authentication per document source. A partner reports deployment in under seven days. Difficulty rises sharply on the upper tiers, where ERP connectors, custom Python blocks, SAML SSO, SCIM provisioning, SIEM integration and VPC or on-premise deployment all require IT involvement. Budget a business analyst for the rules and an integration engineer for anything touching the ERP.
Deployment
Integrations
Supported languages
Behind Nanonets
Fundraising
Social
Resources
All the official URLs gathered for verification and reference.
Alternatives
Tools that compete with or complement Nanonets.
Frequently asked questions
How is a Nanonets agent different from a chatbot or a copilot?
What does Nanonets actually cost?
Is there an API, and is it documented?
Which systems does it connect to?
How many languages can it read?
Where is my data hosted?
Will my documents be used to train Nanonets models?
What compliance certifications does Nanonets hold?
Is a Data Processing Agreement available?
Is there a mobile app, and what is the minimum age?
Should you pick Nanonets?
Nanonets is a substantial product, and the evidence for that is on the site rather than in its slogans. The company is identified, its address and phone number are published, eight separate legal pages are online including a named subprocessor list, the entry pricing is quantified down to the unit price of a single block, the API is publicly documented with prebuilt models, and reference customers are named with figures attached. Few tools in this category expose that much.
What you are buying is document work performed end to end rather than an assistant that helps you do it: the agent reads, validates, matches and writes back into the system of record, and the extraction engine behind it holds first place on a public third-party ranking. For an accounts payable, order management, claims or logistics team drowning in paperwork, that is a serious proposition, and the enterprise controls — SSO, RBAC, SIEM audit logs, private or on-premise deployment — are deep enough to survive a procurement review.
Two reservations deserve to be weighed before signing. The first is contractual: the product pages promise a zero training guarantee, while clause 6.3 of the terms lets Nanonets freely use Derived Data to improve its own products, with an explicit training carve-out only for data coming through Google and Microsoft APIs. The second is economic: beyond the USD 50 of opening credits, the real entry point is USD 100 per month and the bill scales with the number of blocks each document consumes, which makes forecasting harder than a per-seat licence would. Add an uneven legal corpus — terms and security policy from 2020-2021, privacy notice from July 2026 — and the sensible move is to have a legal reader go through the terms alongside the marketing pages before committing volume.
- Choosing a selection results in a full page refresh.
- Opens in a new window.