SOC 2 Type II
ActiveAnnual audit covering security, availability, and confidentiality trust service criteria.
- Independent third-party audit
- Covers security, availability, and confidentiality
- Continuous monitoring and evidence collection
- Report available under NDA for Enterprise customers
GDPR
CompliantFull compliance with the General Data Protection Regulation for EU/EEA data subjects.
- Data Processing Agreement (DPA) available
- Standard Contractual Clauses (SCCs) for international transfers
- Data subject rights: access, erasure, portability, restriction
- Data Protection Officer appointed
- Configurable data retention and logging policies
- EU data residency options available (Enterprise)
HIPAA
EligibleBusiness Associate Agreement (BAA) available for healthcare organizations on Enterprise plan.
- BAA available for Enterprise customers
- PHI-aware guardrails (PII/PHI redaction via Presidio)
- Audit logging for all data access
- Encryption in transit and at rest
PCI DSS
DelegatedPayment card data handled entirely by Stripe — no card numbers touch our servers.
- Stripe handles all PCI-scoped data
- No payment card numbers stored or processed by NemoRouter
- Stripe tokenization for all payment flows
Data Protection Summary
| Measure | Implementation |
|---|---|
| Encryption in transit | TLS 1.2+ (HSTS enforced) |
| Encryption at rest | AES-256 |
| Database isolation | Row-Level Security on all tables |
| API key storage | SHA-256 hashed, shown once at creation |
| Auth | JWT via Supabase Auth |
| Credit safety | Reserve+settle with advisory locks |
| Data retention | Configurable per-org (zero/metadata/full/PII-redacted) |
| Log retention | 90 days (auto-purged daily) |
| Financial records | 7 years (legal obligation) |
Request Compliance Documentation
SOC 2 reports, DPA, BAA, and security questionnaire responses are available for qualified organizations.
Related: Security · Privacy Policy · DPA · Terms of Service