New0% platform fee on Tier 2+ — upgrade from 4% Pay As You Go. Start now

Trust Center

Compliance & Trust

Nemo Router is committed to protecting your data. Here is our compliance posture for the NemoRouter platform.

SOC 2 Type II

Active

Annual audit covering security, availability, and confidentiality trust service criteria.

  • Independent third-party audit
  • Covers security, availability, and confidentiality
  • Continuous monitoring and evidence collection
  • Report available under NDA for Enterprise customers

GDPR

Compliant

Full compliance with the General Data Protection Regulation for EU/EEA data subjects.

  • Data Processing Agreement (DPA) available
  • Standard Contractual Clauses (SCCs) for international transfers
  • Data subject rights: access, erasure, portability, restriction
  • Data Protection Officer appointed
  • Configurable data retention and logging policies
  • EU data residency options available (Enterprise)

HIPAA

Eligible

Business Associate Agreement (BAA) available for healthcare organizations on Enterprise plan.

  • BAA available for Enterprise customers
  • PHI-aware guardrails (PII/PHI redaction via Presidio)
  • Audit logging for all data access
  • Encryption in transit and at rest

PCI DSS

Delegated

Payment card data handled entirely by Stripe — no card numbers touch our servers.

  • Stripe handles all PCI-scoped data
  • No payment card numbers stored or processed by NemoRouter
  • Stripe tokenization for all payment flows

Data Protection Summary

MeasureImplementation
Encryption in transitTLS 1.2+ (HSTS enforced)
Encryption at restAES-256
Database isolationRow-Level Security on all tables
API key storageSHA-256 hashed, shown once at creation
AuthJWT via Supabase Auth
Credit safetyReserve+settle with advisory locks
Data retentionConfigurable per-org (zero/metadata/full/PII-redacted)
Log retention90 days (auto-purged daily)
Financial records7 years (legal obligation)

Request Compliance Documentation

SOC 2 reports, DPA, BAA, and security questionnaire responses are available for qualified organizations.

Related: Security · Privacy Policy · DPA · Terms of Service