How we protect the information our clients trust us with.
Security and compliance are our craft — and how we run our own practice. Nomos OS is built as a working reference implementation of the SOC 2 controls we advise on. Here is what that means in practice, and how to request our current security documentation.
Concrete controls, enforced in the platform.
Multi-factor authentication
Every account — our team and client users alike — must complete MFA. A password on its own never reaches your data.
Encryption in transit & at rest
All traffic is served over TLS and forced to HTTPS (HSTS); stored data is encrypted at rest on managed cloud infrastructure.
Isolation between clients
Separation is enforced in the database with row-level security, so one client’s information is never reachable from another client’s session.
Least-privilege access
People and integrations get the narrowest access the work requires — scoped roles, server-only keys, and narrowly-scoped third-party permissions.
A complete audit trail
Changes to client records are written to an append-only audit log, so there is a durable record of who changed what, and when.
A hardened application
A strict content-security-policy and security headers, a strong password policy, and automatic session expiry — verified on every release.
Security is part of shipping, not an afterthought.
Security review on every change
No change ships without passing a security review against a checklist mapped to the OWASP Top 10 and ASVS — on top of automated gates.
Automated scanning in CI
Every build runs dependency and secret scanning; a vulnerable dependency or a leaked credential fails the pipeline before it can ship.
Threat modeling & risk register
The system is threat-modeled, and accepted risks are tracked in a maintained register with named owners rather than quietly ignored.
Standards-based by design
Built to OWASP, the NIST Secure Software Development Framework, and the SOC 2 Trust Services Criteria — the same criteria we help clients meet.
Run like the programs we build
We hold our own practice to the controls we help clients implement:
- Documented security policies, progressively operationalized inside the platform
- A vendor inventory with a least-privilege review of every service that touches client data
- Periodic access reviews as engagements and staffing change
- A maintained asset inventory and risk register
Data handling & subprocessors
We keep our tooling deliberately small. Client documentation and evidence are hosted on managed cloud infrastructure — an access-controlled database, a private document store, and application hosting. Uploaded files are never public: access is mediated by membership checks and short-lived, single-use links, and shared only with the people who need it for the work.
We hold client information only as long as the engagement needs it, and return or remove it on request. A complete subprocessor list and data-flow detail is available for your vendor review.
Compliance & documentation
For our current compliance status, a security overview, or documentation for a vendor assessment, get in touch and we’ll share what’s relevant to your review.
Request documentationReport a concern
If you believe you’ve found a security issue affecting Nomos Compliance or one of our engagements, please tell us — we investigate every report. Our disclosure contact is also published at /.well-known/security.txt.
business_inquiries@nomos-compliance.com