Trust Center
Security, Privacy, and Compliance at Nulogy
Major brands, manufacturers, and their external supply networks run their production data on Nulogy. Here is how we keep that data secure, available, and compliant, and how to request our security documentation.
Compliance & Certifications
Independently Audited and Privacy-Compliant
Our security is verified by third parties, not just described by us. Here is what each standard means and how Nulogy meets it. Reports are available on request.
SOC 2 Type II
An independent auditor's examination of how our controls protect customer data over time, across security, availability, and confidentiality. Our current report covers January 1 to December 31, 2025, and is available on request.
GDPR
The General Data Protection Regulation is the European Union's law governing how personal data is collected, processed, and stored. Nulogy handles personal data in line with GDPR requirements.
CCPA
The California Consumer Privacy Act gives California residents rights over the personal information companies hold about them. Nulogy supports those rights in how it processes personal data.
PIPEDA
Canada's Personal Information Protection and Electronic Documents Act sets the rules for how private-sector organizations handle personal information. Nulogy operates in line with PIPEDA.
Security Practices
How We Protect Your Data
The controls behind the Nulogy Manufacturing Operating System, from encryption to recovery.
Security Program
A SOC 2 Type II compliant information security program governs how we protect customer data, with controls examined by an independent auditor.
Data Encryption
TLS 1.2 or greater with strong ciphers protects data in transit. Data at rest is encrypted with 256-bit AES.
Infrastructure & Hosting
Hosted on Amazon Web Services across multiple, physically separate availability zones built to operate 24/7.
High Availability
A high-availability architecture built with infrastructure as code, running in redundant availability zones that fail over automatically without interruption.
Business Continuity
Our teams are equipped to operate remotely and in a distributed way, from customer support to on-call and development, if an emergency hits.
Backups & Recovery
Backups run daily, are encrypted at rest, and are retained for 30 days, so your data stays protected and recoverable.
Documentation
Need Our Security Documents?
Detailed documents, including the SOC 2 Type II report, are shared on request. Our security team reviews each request before granting access. No sales call required.
FAQ
Security Questions, Answered
Is Nulogy SOC 2 compliant?
Yes. Nulogy operates a SOC 2 Type II compliant information security program. The SOC report is an independent, third-party examination of the controls that protect customer data. You can request the report.
How does Nulogy encrypt customer data?
Data in transit is protected with TLS 1.2 or greater using strong ciphers. Data at rest is encrypted with 256-bit AES.
Where is Nulogy customer data hosted?
On Amazon Web Services, across multiple physically separate availability zones, so the platform can fail over automatically without interruption.
How do I get a copy of Nulogy's SOC 2 report?
Use the document request page. Our security team reviews each request and approves access to the SOC 2 Type II report and other documentation. No sales call required.
What is Nulogy's backup and recovery policy?
Backups run daily, are encrypted at rest, and are retained for 30 days. Combined with a multi-availability-zone architecture, this keeps customer data protected and recoverable.
Is Nulogy GDPR, CCPA, and PIPEDA compliant?
Yes. Nulogy handles personal data in line with the EU's GDPR, California's CCPA, and Canada's PIPEDA. How we handle personal data is detailed in the Nulogy Privacy Policy, and privacy questions can go to [email protected].
Request Documents
Request Our Security Documentation
We use the details you provide to review and fulfill your document request. See our Privacy Policy.