How we protect your data

Concrete controls, enforced in the platform.

Multi-factor authentication

Every account — our team and client users alike — must complete MFA. A password on its own never reaches your data.

Encryption in transit & at rest

All traffic is served over TLS and forced to HTTPS (HSTS); stored data is encrypted at rest on managed cloud infrastructure.

Isolation between clients

Separation is enforced in the database with row-level security, so one client’s information is never reachable from another client’s session.

Least-privilege access

People and integrations get the narrowest access the work requires — scoped roles, server-only keys, and narrowly-scoped third-party permissions.

A complete audit trail

Changes to client records are written to an append-only audit log, so there is a durable record of who changed what, and when.

A hardened application

A strict content-security-policy and security headers, a strong password policy, and automatic session expiry — verified on every release.

How we build it

Security is part of shipping, not an afterthought.

Security review on every change

No change ships without passing a security review against a checklist mapped to the OWASP Top 10 and ASVS — on top of automated gates.

Automated scanning in CI

Every build runs dependency and secret scanning; a vulnerable dependency or a leaked credential fails the pipeline before it can ship.

Threat modeling & risk register

The system is threat-modeled, and accepted risks are tracked in a maintained register with named owners rather than quietly ignored.

Standards-based by design

Built to OWASP, the NIST Secure Software Development Framework, and the SOC 2 Trust Services Criteria — the same criteria we help clients meet.

Run like the programs we build

We hold our own practice to the controls we help clients implement:

  • Documented security policies, progressively operationalized inside the platform
  • A vendor inventory with a least-privilege review of every service that touches client data
  • Periodic access reviews as engagements and staffing change
  • A maintained asset inventory and risk register

Data handling & subprocessors

We keep our tooling deliberately small. Client documentation and evidence are hosted on managed cloud infrastructure — an access-controlled database, a private document store, and application hosting. Uploaded files are never public: access is mediated by membership checks and short-lived, single-use links, and shared only with the people who need it for the work.

We hold client information only as long as the engagement needs it, and return or remove it on request. A complete subprocessor list and data-flow detail is available for your vendor review.

Compliance & documentation

For our current compliance status, a security overview, or documentation for a vendor assessment, get in touch and we’ll share what’s relevant to your review.

Request documentation

Report a concern

If you believe you’ve found a security issue affecting Nomos Compliance or one of our engagements, please tell us — we investigate every report. Our disclosure contact is also published at /.well-known/security.txt.

business_inquiries@nomos-compliance.com