- SOC 2 Type II. Independently audited security controls covering data protection and operational security. Attestation letter available to enterprise customers under NDA via [email protected].
- Zero Data Retention (ZDR). Request data is processed and not retained beyond fulfilling the request.
- GDPR, CCPA & data rights. Compliant with GDPR, UK GDPR, CCPA/CPRA, and Israel’s Privacy Protection Law. Data subject requests are handled within regulatory timelines via [email protected].
- International data transfers. Covered by the EU Standard Contractual Clauses (2021) and the UK International Data Transfer Addendum.
- DPA & custom contracts. Data Processing Agreements, custom MSAs, and security reviews available to meet procurement requirements. Contact [email protected].
- Security architecture. Zero-trust access model, encryption in transit and at rest, role-based access control (RBAC), and audit trails across the platform.
Compliance & Security
Nimble’s certifications, data protection posture, and security architecture
Nimble is independently audited and built to meet enterprise data protection requirements.