Trust Centre

Compliance

What we have in place today, and what we are working towards. We state only what is true now, and are explicit about what is still on the roadmap.

Today Nuromi aligns with the Australian Privacy Act 1988 and the Australian Privacy Principles, applies GDPR-aligned handling, meets PCI DSS through Stripe, and runs on SOC 2 Type II infrastructure via Supabase. Nuromi's own SOC 2 Type II attestation, ISO 27001, and an IRAP assessment are in progress, with target dates to be confirmed.

In place today

These frameworks apply to Nuromi as it operates now.

Australian Privacy Act 1988 / APPs

In place
Scope
Collection, storage, use, and disclosure of personal information for Nuromi as a service.
Evidence and access
Privacy policy and data handling practices aligned with the Australian Privacy Principles from day one.

GDPR alignment

In place
Scope
Rights of access, correction, portability, and erasure for customers and data subjects in the EU and UK.
Evidence and access
Privacy policy sets out GDPR-aligned handling; available on request for procurement review.

PCI DSS Level 1

In place
Scope
Payment card handling for Nuromi subscriptions.
Evidence and access
Payments are processed exclusively by Stripe. Nuromi never stores or processes card numbers.

SOC 2 Type II (infrastructure layer)

In place
Scope
Hosting and database infrastructure underneath Nuromi, via Supabase.
Evidence and access
Supabase's own SOC 2 Type II attestation covers the infrastructure layer. Available on request.

In progress

These are underway. Target dates are being finalised and are not yet confirmed, so we do not publish specific dates. We will update this page as each is completed.

Nuromi's own SOC 2 Type II attestation

In progress
Scope
An attestation covering Nuromi as an organisation, not only its infrastructure provider.
Evidence and access
In progress, target date to be confirmed. Interim documentation available under NDA.

ISO 27001

In progress
Scope
Information security management system certification for Nuromi.
Evidence and access
In progress, target date to be confirmed.

IRAP assessment

In progress
Scope
Assessment against the Australian Government Information Security Registered Assessors Program controls.
Evidence and access
In progress, target date to be confirmed. Referred to as IRAP assessed, not IRAP certified.

Documentation for procurement

Interim documentation, including the SOC 2 report for our infrastructure layer, a penetration test summary, a security whitepaper, an architecture diagram, and a DPIA, is available to prospective and current customers under a mutual non-disclosure agreement. Email hello@nuromi.ai. See also the Trust Centre and the Data Processing Addendum.

Compliance questions

Is Nuromi SOC 2 certified?
The infrastructure Nuromi runs on is covered by Supabase's SOC 2 Type II attestation. Nuromi's own organisation-level SOC 2 Type II attestation is in progress, with a target date to be confirmed. We do not claim that Nuromi itself is SOC 2 certified today.
Is Nuromi ISO 27001 certified?
Not yet. ISO 27001 certification is in progress, with a target date to be confirmed. We do not claim ISO 27001 certification for Nuromi today.
Is Nuromi IRAP assessed?
An IRAP assessment is in progress, with a target date to be confirmed. We describe this as IRAP assessed rather than IRAP certified, in line with how the program works.
What is in place today?
Today, Nuromi aligns with the Australian Privacy Act 1988 and the Australian Privacy Principles, applies GDPR-aligned handling, meets PCI DSS through Stripe for payments, and runs on SOC 2 Type II infrastructure via Supabase. The rest of the frameworks are on the roadmap.