Trust Centre
Compliance
What we have in place today, and what we are working towards. We state only what is true now, and are explicit about what is still on the roadmap.
Today Nuromi aligns with the Australian Privacy Act 1988 and the Australian Privacy Principles, applies GDPR-aligned handling, meets PCI DSS through Stripe, and runs on SOC 2 Type II infrastructure via Supabase. Nuromi's own SOC 2 Type II attestation, ISO 27001, and an IRAP assessment are in progress, with target dates to be confirmed.
In place today
These frameworks apply to Nuromi as it operates now.
Australian Privacy Act 1988 / APPs
In place- Scope
- Collection, storage, use, and disclosure of personal information for Nuromi as a service.
- Evidence and access
- Privacy policy and data handling practices aligned with the Australian Privacy Principles from day one.
GDPR alignment
In place- Scope
- Rights of access, correction, portability, and erasure for customers and data subjects in the EU and UK.
- Evidence and access
- Privacy policy sets out GDPR-aligned handling; available on request for procurement review.
PCI DSS Level 1
In place- Scope
- Payment card handling for Nuromi subscriptions.
- Evidence and access
- Payments are processed exclusively by Stripe. Nuromi never stores or processes card numbers.
SOC 2 Type II (infrastructure layer)
In place- Scope
- Hosting and database infrastructure underneath Nuromi, via Supabase.
- Evidence and access
- Supabase's own SOC 2 Type II attestation covers the infrastructure layer. Available on request.
In progress
These are underway. Target dates are being finalised and are not yet confirmed, so we do not publish specific dates. We will update this page as each is completed.
Nuromi's own SOC 2 Type II attestation
In progress- Scope
- An attestation covering Nuromi as an organisation, not only its infrastructure provider.
- Evidence and access
- In progress, target date to be confirmed. Interim documentation available under NDA.
ISO 27001
In progress- Scope
- Information security management system certification for Nuromi.
- Evidence and access
- In progress, target date to be confirmed.
IRAP assessment
In progress- Scope
- Assessment against the Australian Government Information Security Registered Assessors Program controls.
- Evidence and access
- In progress, target date to be confirmed. Referred to as IRAP assessed, not IRAP certified.
Documentation for procurement
Interim documentation, including the SOC 2 report for our infrastructure layer, a penetration test summary, a security whitepaper, an architecture diagram, and a DPIA, is available to prospective and current customers under a mutual non-disclosure agreement. Email hello@nuromi.ai. See also the Trust Centre and the Data Processing Addendum.
Compliance questions
- Is Nuromi SOC 2 certified?
- The infrastructure Nuromi runs on is covered by Supabase's SOC 2 Type II attestation. Nuromi's own organisation-level SOC 2 Type II attestation is in progress, with a target date to be confirmed. We do not claim that Nuromi itself is SOC 2 certified today.
- Is Nuromi ISO 27001 certified?
- Not yet. ISO 27001 certification is in progress, with a target date to be confirmed. We do not claim ISO 27001 certification for Nuromi today.
- Is Nuromi IRAP assessed?
- An IRAP assessment is in progress, with a target date to be confirmed. We describe this as IRAP assessed rather than IRAP certified, in line with how the program works.
- What is in place today?
- Today, Nuromi aligns with the Australian Privacy Act 1988 and the Australian Privacy Principles, applies GDPR-aligned handling, meets PCI DSS through Stripe for payments, and runs on SOC 2 Type II infrastructure via Supabase. The rest of the frameworks are on the roadmap.