Trust Centre

Trust, security, and compliance

Everything your IT, security, and compliance team needs to evaluate Nuromi, in one place. Privacy by design, not privacy by policy.

Nuromi keeps Australian customer data in region on Supabase Sydney and Vercel Sydney edge, encrypts it with TLS 1.3 in transit and AES-256 at rest, isolates every tenant with database Row-Level Security, and sends the AI only server-side aggregates rather than raw records. This is the single place for IT, security, and procurement teams to evaluate how Nuromi handles data.

Trust shelf

Privacy Act 1988 alignedGDPR alignedSOC 2 Type II infra (Supabase)PCI DSS payments (Stripe)Raw data never reaches AI models99.9% uptime target

How your data is protected

Australian data residency

Nuromi runs on regional infrastructure. For Australian customers that is Supabase Sydney (AWS ap-southeast-2) and Vercel Sydney edge. Records, logs, and compliance documents stay in region. Built to align with the Australian Privacy Act 1988 and the Australian Privacy Principles. US, UK, and EU residency is available on request.

Encryption in transit and at rest

All data in transit is protected with TLS 1.3. All data at rest is encrypted with AES-256. This applies to every piece of information Nuromi handles, from financial records to attendance, inspection scores, and incident data.

Data minimisation and how AI uses your data

When the AI analyses structured data, it does not receive your raw records. Spreadsheets and connected systems are profiled and aggregated server-side into totals, counts, and trends, and only that aggregated context crosses to the AI. Documents you upload to be read as documents are the one exception: Anthropic's Claude reads the document itself to extract its figures. Every call to Claude requests zero data retention, and Anthropic does not train on customer data. Voice-note transcription, only for customers with voice notes enabled, runs on Deepgram with zero retention.

Tenant isolation (Row-Level Security)

Database-level Row-Level Security makes it architecturally impossible for one organisation's data to appear in another's view. If you run client portals, each client sees only their own data, regardless of how permissions are configured.

Role-based access

You control who sees what. Executives, managers, and frontline stakeholders each get different access levels. Dashboard views, data exports, and AI reports are permission-controlled and enforced at the database level, not just hidden in the interface.

Passwordless by default

Magic-link sign-in is the default and the only way to create an account, so most people never set a password. Team members who want a faster or stronger sign-in can add a passkey (Face ID, Touch ID, or Windows Hello), which is phishing-resistant by design, or set an optional password of their own choosing in Settings. Any password chosen is stored only as a salted hash by our authentication provider, Supabase Auth, never in our own database.

Credential vault and zero standing access

Every OAuth integration token is stored in Supabase Vault, a separately encrypted secrets store, never in application code or environment variables. No Nuromi team member has standing access to production customer data. Any access is time-limited, approved, and fully logged.

Audit trail and breach notification

Every login, data access, and AI-generated report is logged with timestamp, user identity, and action taken. In the event of a confirmed breach, affected customers are notified within 72 hours, in line with the Privacy Act 1988 Notifiable Data Breaches scheme and GDPR-aligned practice.

Data export and no lock-in

Your data is exportable in standard formats at any time. A full extract in CSV or JSON is available immediately. Payment data is handled exclusively by Stripe (PCI DSS Level 1); Nuromi never stores or processes card numbers.

Trust summary

Plain-language answers to the questions security and procurement teams ask most.

Is Nuromi SOC 2 certified?
The infrastructure Nuromi runs on is covered by Supabase's SOC 2 Type II attestation. Nuromi's own organisation-level SOC 2 Type II attestation is in progress, with a target date to be confirmed. See the compliance roadmap.
Is Nuromi ISO 27001 certified?
Not yet. ISO 27001 certification is in progress, with a target date to be confirmed. We do not claim ISO 27001 certification today.
Is a Data Processing Addendum available?
Yes. A DPA summary is published at /dpa and the full DPA template is available on request by emailing hello@nuromi.ai.
Who are Nuromi sub-processors?
Supabase (database and vault, Sydney), Anthropic (AI analysis, zero data retention), Deepgram (voice-note transcription, zero data retention, only when enabled), Stripe (payments, PCI DSS Level 1), Vercel (hosting), Nango (connector OAuth), and Resend (transactional email). The full register is at /trust/subprocessors.
How does Nuromi use my data with AI?
For structured data, only server-side aggregates (totals, counts, trends) are sent to the AI, never raw records. Documents you upload are read directly by Anthropic Claude, with zero data retention requested on every call, and Claude does not train on customer data. There is no Google Gemini fallback. Voice-note transcription, only for customers with voice notes enabled, runs on Deepgram with zero retention.
How is data encrypted?
TLS 1.3 in transit and AES-256 at rest, applied to all data Nuromi handles.
How is access controlled?
Database-level Row-Level Security isolates every tenant, role-based access controls who sees what, and magic-link sign-in remains the default, so most accounts never have a password to protect. Anyone who opts into a passkey, which is phishing-resistant by design, or an optional password stores nothing with us directly: Supabase Auth, our authentication provider, holds any password only as a salted hash. OAuth tokens live in Supabase Vault with zero standing team access.
What is your incident response and breach notification?
Every access is logged in a full audit trail. In the event of a confirmed breach, affected customers are notified within 72 hours, in line with the Privacy Act 1988 Notifiable Data Breaches scheme and GDPR-aligned practice.

Sub-processors

The vendors that help run Nuromi. The full register with regions and certifications is at /trust/subprocessors.

SupabaseAnthropicDeepgramStripeVercelNangoResend

Documentation under NDA

The following are available to prospective and current customers under a mutual non-disclosure agreement:

  • SOC 2 report
  • Penetration test summary
  • Security whitepaper
  • Architecture diagram
  • Data protection impact assessment (DPIA)

Need a security questionnaire completed?

We are happy to walk your technical stakeholders through the architecture, complete a security questionnaire, or provide documentation for procurement and due diligence.

Request a security questionnaire

Third-party data

Based on Australian Bureau of Statistics data. State and territory boundaries used in map-style dashboard widgets are derived from the ABS Australian Statistical Geography Standard (ASGS), licensed under Creative Commons Attribution 4.0 International.