> ## Documentation Index
> Fetch the complete documentation index at: https://docs.nimbleway.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Compliance & Security

> Nimble's certifications, data protection posture, and security architecture

Nimble is independently audited and built to meet enterprise data protection requirements.

* **SOC 2 Type II.** Independently audited security controls covering data protection and operational security. Attestation letter available to enterprise customers under NDA via [security@nimbleway.com](mailto:security@nimbleway.com).
* **Zero Data Retention (ZDR).** Request data is processed and not retained beyond fulfilling the request.
* **GDPR, CCPA & data rights.** Compliant with GDPR, UK GDPR, CCPA/CPRA, and Israel's Privacy Protection Law. Data subject requests are handled within regulatory timelines via [privacy@nimbleway.com](mailto:privacy@nimbleway.com).
* **International data transfers.** Covered by the EU Standard Contractual Clauses (2021) and the UK International Data Transfer Addendum.
* **DPA & custom contracts.** Data Processing Agreements, custom MSAs, and security reviews available to meet procurement requirements. Contact [privacy@nimbleway.com](mailto:privacy@nimbleway.com).
* **Security architecture.** Zero-trust access model, encryption in transit and at rest, role-based access control (RBAC), and audit trails across the platform.

Full trust overview: [nimbleway.com/trust](https://www.nimbleway.com/trust)
