Our posture
We describe here the controls that are actually in place today. Where something is a roadmap item rather than a control, we say so instead of implying a certification we do not hold: Nomi is not currently SOC 2 or ISO 27001 certified, and we will not claim otherwise on a page a customer's security team is reading.
Architecture
- One authorisation path. Our own administration interface is held to the same checks as a customer integration, with no privileged route around them.
- Sessions are not readable by the page. Administrative sessions are established and held server-side; nothing a browser script can reach carries the authority to act.
- Issued credentials are served, not linked. The file behind a credential is delivered through an authorised request rather than a public address, so possession of a link is not possession of the credential.
- The server decides, not the screen. An operation the server would refuse is not offered by the interface — a revoked credential offers none — so the rule is enforced in one place rather than mirrored in two.
- Tenant isolation. Every record belongs to one organisation, and every request is answered only within the organisation it was authenticated for.
Signing material and secrets
A credential is trustworthy because of what signs it. Signing material is sealed in the database rather than left on a container filesystem, and the resolver reads the database before it looks anywhere else — a redeploy cannot silently drop a key onto disk or lose one. Secrets and platform credentials are held as environment configuration in the hosting provider, never in the repository.
API keys are stored hashed; we cannot read one back to you, and a lost key is rotated rather than recovered. Webhook payloads are signed so your endpoint can verify that a delivery came from us and has not been replayed.
Access control
- Role-based access in the console, so an operator who issues credentials need not hold the rights that mint API keys.
- Sign-in supports single sign-on and passkeys, and sensitive operations require a step-up re-authentication.
- Directory-driven provisioning (SCIM and connectors) so that access follows the customer's own joiner and leaver process rather than a spreadsheet.
- Access to production by our staff is limited to the people who need it to operate and support the platform, and is used for that purpose only.
Data protection
Traffic is encrypted in transit with TLS. Data at rest — the database and object storage — is encrypted by the infrastructure providers listed below. Uploaded artwork and photographs live in object storage rather than on an ephemeral container disk, and are served through authenticated routes rather than public URLs.
What we hold, for how long, and how it is deleted is set out in the Privacy Policy.
Audit trail
Security-relevant actions — issuing, updating, suspending, revoking, key creation, member and role changes — are recorded as events with the actor and the time, exportable from the console. Audit events are retained for up to 24 months and are not deletable from the interface; an audit trail a user can erase is not an audit trail.
Infrastructure and vendors
We run on managed infrastructure rather than machines we rack ourselves. The current providers, what each one does and where it operates are listed in the Privacy Policy, and each is bound by a written contract limiting it to our instructions. Customers may ask to be notified before a new subprocessor is appointed.
Incident response
If we become aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration or unauthorised disclosure of personal data we process for a customer, we will notify that customer without undue delay and in any event within 72 hours of becoming aware, with what we know: what happened, which data and which people are affected, what we are doing, and what we recommend you do. We will keep the customer updated as the picture develops, and we will not wait for a complete picture before telling you.
Reporting a vulnerability
If you have found a security issue, tell us at security@nomi-tech.com. Include what you found, how to reproduce it, and how we can reach you. We acknowledge within 3 business days, keep you informed while we fix it, and are glad to credit you when it is resolved.
Your side of the line
Most incidents in a platform like this start on the customer's side. Rotate API keys when someone leaves, give Users the narrowest role that lets them work, keep your identity provider's multi-factor requirements on, verify webhook signatures rather than trusting the payload, and do not send us data the platform is not built for — the list is in clause 5 of the Terms.
No system is perfectly secure. These controls reduce risk; they do not eliminate it, and we do not represent that they do.
Contact
- Security reports: security@nomi-tech.com
- Abuse of the service: abuse@nomi-tech.com
- Security questionnaires and due diligence: legal@nomi-tech.com
In the United States
This page is the the United States edition. The service and the agreement are the same everywhere; what follows is what is specific to where you are.
Invoices to customers in the United States are drawn in USD. No indirect tax is applied by default. Where you are registered to pay one, set the rate on your billing settings and it appears on every invoice from then on.
Your own obligations as a data controller sit under state privacy laws (CCPA/CPRA and equivalents). Nomi processes credential data on your instructions, keeps a queryable record of every action taken on it, and can delete or export a single person's data on request — which is what answering under that law requires of a processor.
The agreement itself is governed by the laws of the Republic of Costa Rica, and disputes go to the courts of San José, Costa Rica. That is the law of the company that provides the service, and it does not take away any right you have under the mandatory consumer or data-protection law of your own country.