Nebula Trust Center

View Nebula Trust Center's compliance certifications, security documentation, and subprocessors on their public trust center.

Powered by Wolfia. Review compliance certifications, security policies, subprocessors, and request access to detailed documentation.

Skip to main content
Nebula Trust Center

Nebula Trust Center

Access control

Restricts system and data access to authorized users based on business need and approved permissions.

Least privilege access

Access is limited to the minimum level needed for job responsibilities. This reduces unnecessary exposure to sensitive systems and helps contain the impact of compromised accounts.

Role-based and approved access provisioning

Default access is aligned to job roles, while exceptions require documented business justification and formal approval. This creates a consistent access model with a clear approval trail.

Secure authentication controls

Nebula.io applies strong authentication measures such as multi-factor authentication where feasible, uses single sign-on where applicable, and enforces secure logon protections on critical systems. These controls help reduce credential-based attacks and improve account security.

Access review and timely removal

User access rights are reviewed at least annually, and access is revoked or adjusted when employment or responsibilities change. Regular review and prompt deprovisioning help prevent lingering or excessive permissions.

Encryption and key management

Protects sensitive data and credentials during storage, transmission, and key handling.

Encryption at rest

Sensitive data stored in infrastructure, cloud services, and endpoint devices is protected using managed encryption mechanisms. This helps keep data unreadable if underlying storage is accessed improperly.

Encryption in transit

Data moving across networks and internet-facing services is protected with secure transmission protocols. This preserves confidentiality for customer and internal communications.

Password and credential protection

Authentication secrets are encrypted during transmission and protected when stored using strong hashing practices. These safeguards reduce the likelihood of credential misuse if systems are exposed.

Cryptographic key management

Encryption keys are generated, stored, protected, and rotated through controlled processes. Strong key governance helps maintain the effectiveness of Nebula.io's encryption controls over time.

Secure development

Builds security and privacy into software from design through testing and release.

Secure development lifecycle

Security is incorporated across requirement gathering, design, development, testing, implementation, and maintenance. Integrating security throughout the lifecycle helps reduce risk before software reaches production.

Security and privacy requirements by design

Teams define security, privacy, availability, and reliability requirements at the start of system work. Addressing these expectations early supports more resilient and compliant design decisions.

Segregated development and testing environments

Development and testing are performed in environments isolated from production. Environment separation lowers the chance of unauthorized changes or test activity affecting live customer services.

Secure coding and test data controls

Developers are expected to follow secure coding practices, use current libraries, and avoid using operational or confidential data in testing unless it is protected and removed afterward. These practices help prevent common software weaknesses and unnecessary data exposure.

Change and vulnerability management

Controls production changes and remediates weaknesses before they can materially affect service or data protection.

Formal change management

Changes affecting software, infrastructure, networks, and security documentation are documented, approved, tested, and tracked before deployment. Controlled change processes reduce disruption and unauthorized modifications.

Segregation of duties for changes

The same individual cannot request, approve, and implement a change. Separating these responsibilities reduces the risk of error, abuse, and unreviewed production updates.

Pre-deployment testing

Changes and patches are tested in isolated, representative environments before deployment whenever feasible. Testing helps identify operational and security issues before they affect customers.

Vulnerability management and risk-based remediation

Nebula.io maintains a documented vulnerability management process, uses trusted sources and scans to identify issues, and prioritizes remediation based on severity and likelihood. Higher-risk fixes are validated after deployment to confirm the issue is resolved.

Logging and monitoring

Provides auditable visibility into security-relevant activity and supports timely detection of abnormal conditions.

Security event logging

Operational systems are configured to record security-relevant activities and system events where feasible. These records support accountability, investigations, and ongoing oversight.

Access and privileged activity monitoring

Use of privileged accounts, unauthorized access attempts, policy violations, and relevant traffic are monitored to identify potentially harmful activity sooner. Early visibility helps teams respond before issues spread.

Protected log retention

Logs are retained securely for required legal and contractual periods and protected against tampering or unauthorized access. Preserving trustworthy records supports audits and incident investigations.

Automated alerts and anomaly escalation

Detective controls generate alerts when thresholds are breached or asset security controls fail, and anomalies are escalated for corrective action. This improves response speed when conditions drift from expected baselines.

Business continuity and disaster recovery

Helps restore services and data within acceptable timeframes after major outages or disasters.

Business continuity and disaster recovery plan

Nebula.io maintains a structured plan to restore production services after extended outages or disasters. Defined recovery processes help shorten disruption and support service resilience.

Geographically redundant backups

Production data is backed up regularly and stored in locations separate from the production environment, including geographically redundant storage. This improves recoverability if a primary environment becomes unavailable.

Backup restoration and disaster recovery drills

Nebula.io performs restoration exercises and mock disaster recovery drills to verify that backups can be used and teams can invoke the plan effectively. These exercises also evaluate recovery objectives during testing.

Disaster declaration and stakeholder communication

Authorized personnel can declare a disaster, activate recovery teams, and communicate with internal stakeholders, customers, and regulatory bodies as necessary. Clear escalation and communication responsibilities help coordinate response during prolonged outages.

Incident response

Enables timely reporting, investigation, containment, and improvement following security incidents.

Formal incident response process

Nebula.io maintains a documented process with defined roles, responsibilities, and steps for responding to information security incidents. A standardized approach supports timely and consistent handling.

Incident reporting and tracking

Employees, contractors, and other parties are provided official channels and guidance for reporting security events, and incidents are recorded in an incident management system. Accessible reporting and centralized tracking improve visibility and accountability.

Incident assessment and coordinated response

Reported incidents are classified using predefined criteria, and response activities cover identification, containment, investigation, resolution, and corrective action. Structured response helps reduce operational and security impact.

Stakeholder notification and post-incident learning

Response procedures include required stakeholder notifications, preservation of legal evidence, and periodic analysis of past incidents to strengthen future prevention measures. These practices support both compliance and continuous improvement.

Compliance and auditing

Demonstrates governance through mapped compliance requirements, independent review, and tracked remediation.

Compliance framework alignment

Nebula.io states that its information security management system is operated in alignment with applicable legal, contractual, and industry requirements, including SSAE 18 (SOC 2). This helps customers assess the maturity of the overall control environment.

Independent security audits

Periodic audits are performed by qualified and independent auditors to assess adherence to information security policies and standards. Independent review provides additional assurance beyond internal checks alone.

Annual technical compliance assessments

A competent third party and the engineering team conduct annual technical reviews of networks and production systems to identify vulnerabilities. Regular external assessment strengthens verification of security controls.

Corrective actions and management review

Audit findings, incidents, and nonconformances are tracked through corrective and preventive action processes until closure is verified, and results are reviewed by senior management. This helps ensure issues are remediated and kept visible at the leadership level.

Asset and data management

Maintains accountability for systems and information so protections can be applied according to sensitivity and criticality.

Comprehensive asset inventory

Nebula.io maintains an up-to-date inventory of information assets, including systems, software, repositories, and devices used to access company data. Strong inventory practices are foundational to protecting what the organization depends on.

Asset ownership and periodic review

Each information asset has an identified owner responsible for its security, use, and maintenance, and infrastructure assets and critical systems are reviewed at least annually for accuracy. Named accountability helps keep asset records and protections current.

Data classification and labeling

Information is classified based on sensitivity, business value, legal requirements, and operational criticality, and asset owners must label data according to its classification. Clear classification supports consistent handling and protection across the organization.

Removable media restrictions

Use of removable media to transfer sensitive customer data is prohibited. Restricting portable storage lowers the risk of data loss, uncontrolled copying, and accidental disclosure.

Endpoint and remote work security

Extends baseline protections to user devices and remote work practices that can affect customer data.

Endpoint patching and malware protection

Devices used to access critical systems must have critical updates installed and active antivirus protection. Keeping endpoints current and protected reduces the likelihood of compromise from common threats.

Full disk encryption and device access controls

Work devices must use disk encryption, strong passwords, and automatic screen locking after inactivity. These baseline protections help keep stored information and unattended devices secure.

Lost or stolen device response

Lost, stolen, or damaged devices must be reported immediately so access can be restricted or revoked. Rapid response helps limit exposure when hardware is no longer under user control.

Endpoint compliance reviews and remote work safeguards

Endpoints are subject to reviews, audits, and monitoring for compliance, and remote personnel must secure devices and prevent unauthorized viewing or overhearing of customer data. This extends device governance beyond the office environment.

Network security

Protects production networks through controlled access, segmentation, encrypted administration, and external review.

Restricted production network access

Access to production networks is limited and reviewed on a periodic basis. Tight control over network entry points helps reduce unnecessary exposure to critical environments.

Encrypted remote administrative access

Remote diagnostic and configuration access is limited to dedicated management paths and encrypted application-layer protocols. This helps protect administrative activity from interception or misuse.

Network segmentation

Network domains are segregated and data flows between them are controlled through secure gateways. Segmentation reduces the blast radius if one part of the environment is affected.

Network monitoring and independent assessments

Relevant network logs are monitored, anomalies are raised as security incidents where applicable, and annual third-party assessments are followed by remediation testing. Ongoing oversight and external validation help confirm that network defenses remain effective.

Privacy and data lifecycle

Supports lawful handling, retention, deletion, and accountability for customer and personal data.

Personal data protection compliance

Nebula.io commits to protecting personal data and privacy in line with applicable laws, regulations, and contractual requirements. This supports customer expectations around lawful and responsible data handling.

Data retention schedules

Retention periods are defined based on classification and applicable obligations, and data is not kept longer than necessary for operational, contractual, or legal purposes. This reduces long-term exposure and supports defensible data management.

Authenticated deletion requests

Customer or user deletion requests are validated before action is taken, and requests are evaluated for legal and contractual feasibility. Verification helps prevent unauthorized or improper deletion.

Secure deletion and deletion logging

When data must be removed, Nebula.io uses secure deletion methods and may anonymize information where permitted, while maintaining logs of deletion requests and actions taken. These practices provide accountability for data lifecycle decisions.

Risk management

Prioritizes security decisions through formal risk assessment, ownership, and treatment.

Formal risk assessments

Nebula.io conducts structured risk assessments that identify threats, quantify likelihood and impact, and document mitigation plans. This helps security efforts focus on the risks most relevant to the business and its customers.

Annual risk review and continuous improvement

Risk assessments are performed at least annually and updated using lessons from audits and incidents. A regular cadence helps keep the risk picture current as the environment changes.

Risk ownership and residual risk treatment

Risks are assigned to owners, reviewed with management, and evaluated after mitigation for acceptance, transfer, or additional control implementation. Clear ownership improves accountability for risk decisions.

Third-party risk consideration

Risk assessments explicitly consider risks introduced by third-party vendors. Including external dependencies helps avoid blind spots in the broader control environment.

Physical and workplace security

Reduces exposure in office and public work settings while keeping production systems outside office premises.

Public workspace confidentiality safeguards

Employees working in public locations are instructed to take precautions against visual eavesdropping and other exposure risks. This helps protect sensitive information in lower-control environments.

Cloud-hosted production security

Production systems and customer data are hosted with cloud infrastructure providers rather than on office premises, relying on provider physical security controls. This reduces dependence on office facilities for protecting customer environments.

Clean desk and print restrictions

Sensitive customer data, passwords, and security keys are not left exposed, and printing classified customer data is prohibited. These practices help prevent accidental disclosure in shared spaces.