Back to Home
Enterprise-Grade Security

Security & Trust Center

Your data security is our top priority. We maintain the highest standards of security, compliance, and transparency to protect your organization.

Certifications & Compliance

Certified

SOC 2 Type II

January 2026

Certified

ISO 27001:2022

December 2025

In Progress

FedRAMP Ready

Q2 2026

Certified

GDPR Compliant

Ongoing

Certified

HIPAA Compliant

Ongoing

Certified

PCI DSS Level 1

November 2025

Security Practices

Data Encryption

AES-256 encryption at rest, TLS 1.3 in transit. All customer data encrypted with customer-managed keys (BYOK available).

Zero Trust Architecture

Principle of least privilege, continuous verification, micro-segmentation across all NISSI infrastructure.

Security Monitoring

24/7 SOC monitoring, automated threat detection on our own infrastructure using NISSI's platform (we eat our own dog food).

Data Residency

Choose where your data lives: US, EU, UK, or Asia-Pacific regions. No cross-region data transfer without consent.

Third-Party Audits

Annual penetration testing by independent security firms. Quarterly vulnerability assessments and security reviews.

Bug Bounty Program

Active HackerOne program with $50,000 max bounty. 120+ security researchers protecting NISSI infrastructure.

Infrastructure Security

Cloud Infrastructure

  • • Hosted on AWS with multi-region redundancy
  • • 99.99% uptime SLA with automatic failover
  • • DDoS protection via AWS Shield Advanced
  • • WAF rules blocking 10M+ malicious requests/day

Application Security

  • • Automated SAST/DAST scanning in CI/CD
  • • Dependency scanning for vulnerabilities
  • • Code signing for all production releases
  • • Immutable infrastructure with container security

Access Control

  • • MFA required for all employee access
  • • Role-based access control (RBAC)
  • • Just-in-time privileged access
  • • Complete audit logging of all access

Incident Response

  • • 24/7 security operations center (SOC)
  • • <15 minute incident response time
  • • Quarterly disaster recovery drills
  • • Transparent breach notification policy

Available Reports & Documentation

SOC 2 Type II Report

January 2026

Penetration Test Results

December 2025

ISO 27001 Certificate

December 2025

GDPR DPA Template

Always Current

Security Researchers Welcome

We run an active bug bounty program on HackerOne. Help us keep NISSI secure and earn up to $50,000 for critical vulnerabilities.

120+
Security Researchers
$50K
Max Bounty
72
Vulnerabilities Fixed

Questions About Security?

Our security team is here to answer any questions about our practices, certifications, or compliance.