Nebula Trust Center
Certifications
Does your team answer security questionnaires too? Wolfia answers them for you and runs trust centers
Documentation
Certifications
Security
Subprocessors





Controls
Restricts system and data access to authorized users based on business need and approved permissions.
Protects sensitive data and credentials during storage, transmission, and key handling.
Builds security and privacy into software from design through testing and release.
Frequently asked security questions
Is Nebula secure?
Nebula operates this public trust center. It publishes 2 independent compliance certifications, security documentation available on request, and a published list of its subprocessors.
Is Nebula SOC 2 compliant?
Yes. Nebula maintains SOC 2 Type II compliance. You can review this in the compliance section of this trust center.
Who are Nebula's subprocessors?
Nebula discloses its subprocessors in this trust center, including Elastic, googlecloudplatform.com, and Kombo. See the subprocessors section for the complete list.
How do I request Nebula's security documentation?
You can request access to Nebula's security documentation directly through this trust center. Submit an access request and the Nebula team reviews and grants access.
Does your team answer security questionnaires too? Wolfia answers them for you and runs trust centers
Controls
Access control
Restricts system and data access to authorized users based on business need and approved permissions.
Access is limited to the minimum level needed for job responsibilities. This reduces unnecessary exposure to sensitive systems and helps contain the impact of compromised accounts.
Default access is aligned to job roles, while exceptions require documented business justification and formal approval. This creates a consistent access model with a clear approval trail.
Nebula.io applies strong authentication measures such as multi-factor authentication where feasible, uses single sign-on where applicable, and enforces secure logon protections on critical systems. These controls help reduce credential-based attacks and improve account security.
User access rights are reviewed at least annually, and access is revoked or adjusted when employment or responsibilities change. Regular review and prompt deprovisioning help prevent lingering or excessive permissions.
Encryption and key management
Protects sensitive data and credentials during storage, transmission, and key handling.
Sensitive data stored in infrastructure, cloud services, and endpoint devices is protected using managed encryption mechanisms. This helps keep data unreadable if underlying storage is accessed improperly.
Data moving across networks and internet-facing services is protected with secure transmission protocols. This preserves confidentiality for customer and internal communications.
Authentication secrets are encrypted during transmission and protected when stored using strong hashing practices. These safeguards reduce the likelihood of credential misuse if systems are exposed.
Encryption keys are generated, stored, protected, and rotated through controlled processes. Strong key governance helps maintain the effectiveness of Nebula.io's encryption controls over time.
Secure development
Builds security and privacy into software from design through testing and release.
Security is incorporated across requirement gathering, design, development, testing, implementation, and maintenance. Integrating security throughout the lifecycle helps reduce risk before software reaches production.
Teams define security, privacy, availability, and reliability requirements at the start of system work. Addressing these expectations early supports more resilient and compliant design decisions.
Development and testing are performed in environments isolated from production. Environment separation lowers the chance of unauthorized changes or test activity affecting live customer services.
Developers are expected to follow secure coding practices, use current libraries, and avoid using operational or confidential data in testing unless it is protected and removed afterward. These practices help prevent common software weaknesses and unnecessary data exposure.
Change and vulnerability management
Controls production changes and remediates weaknesses before they can materially affect service or data protection.
Changes affecting software, infrastructure, networks, and security documentation are documented, approved, tested, and tracked before deployment. Controlled change processes reduce disruption and unauthorized modifications.
The same individual cannot request, approve, and implement a change. Separating these responsibilities reduces the risk of error, abuse, and unreviewed production updates.
Changes and patches are tested in isolated, representative environments before deployment whenever feasible. Testing helps identify operational and security issues before they affect customers.
Nebula.io maintains a documented vulnerability management process, uses trusted sources and scans to identify issues, and prioritizes remediation based on severity and likelihood. Higher-risk fixes are validated after deployment to confirm the issue is resolved.
Logging and monitoring
Provides auditable visibility into security-relevant activity and supports timely detection of abnormal conditions.
Operational systems are configured to record security-relevant activities and system events where feasible. These records support accountability, investigations, and ongoing oversight.
Use of privileged accounts, unauthorized access attempts, policy violations, and relevant traffic are monitored to identify potentially harmful activity sooner. Early visibility helps teams respond before issues spread.
Logs are retained securely for required legal and contractual periods and protected against tampering or unauthorized access. Preserving trustworthy records supports audits and incident investigations.
Detective controls generate alerts when thresholds are breached or asset security controls fail, and anomalies are escalated for corrective action. This improves response speed when conditions drift from expected baselines.
Business continuity and disaster recovery
Helps restore services and data within acceptable timeframes after major outages or disasters.
Nebula.io maintains a structured plan to restore production services after extended outages or disasters. Defined recovery processes help shorten disruption and support service resilience.
Production data is backed up regularly and stored in locations separate from the production environment, including geographically redundant storage. This improves recoverability if a primary environment becomes unavailable.
Nebula.io performs restoration exercises and mock disaster recovery drills to verify that backups can be used and teams can invoke the plan effectively. These exercises also evaluate recovery objectives during testing.
Authorized personnel can declare a disaster, activate recovery teams, and communicate with internal stakeholders, customers, and regulatory bodies as necessary. Clear escalation and communication responsibilities help coordinate response during prolonged outages.
Incident response
Enables timely reporting, investigation, containment, and improvement following security incidents.
Nebula.io maintains a documented process with defined roles, responsibilities, and steps for responding to information security incidents. A standardized approach supports timely and consistent handling.
Employees, contractors, and other parties are provided official channels and guidance for reporting security events, and incidents are recorded in an incident management system. Accessible reporting and centralized tracking improve visibility and accountability.
Reported incidents are classified using predefined criteria, and response activities cover identification, containment, investigation, resolution, and corrective action. Structured response helps reduce operational and security impact.
Response procedures include required stakeholder notifications, preservation of legal evidence, and periodic analysis of past incidents to strengthen future prevention measures. These practices support both compliance and continuous improvement.
Compliance and auditing
Demonstrates governance through mapped compliance requirements, independent review, and tracked remediation.
Nebula.io states that its information security management system is operated in alignment with applicable legal, contractual, and industry requirements, including SSAE 18 (SOC 2). This helps customers assess the maturity of the overall control environment.
Periodic audits are performed by qualified and independent auditors to assess adherence to information security policies and standards. Independent review provides additional assurance beyond internal checks alone.
A competent third party and the engineering team conduct annual technical reviews of networks and production systems to identify vulnerabilities. Regular external assessment strengthens verification of security controls.
Audit findings, incidents, and nonconformances are tracked through corrective and preventive action processes until closure is verified, and results are reviewed by senior management. This helps ensure issues are remediated and kept visible at the leadership level.
Asset and data management
Maintains accountability for systems and information so protections can be applied according to sensitivity and criticality.
Nebula.io maintains an up-to-date inventory of information assets, including systems, software, repositories, and devices used to access company data. Strong inventory practices are foundational to protecting what the organization depends on.
Each information asset has an identified owner responsible for its security, use, and maintenance, and infrastructure assets and critical systems are reviewed at least annually for accuracy. Named accountability helps keep asset records and protections current.
Information is classified based on sensitivity, business value, legal requirements, and operational criticality, and asset owners must label data according to its classification. Clear classification supports consistent handling and protection across the organization.
Use of removable media to transfer sensitive customer data is prohibited. Restricting portable storage lowers the risk of data loss, uncontrolled copying, and accidental disclosure.
Endpoint and remote work security
Extends baseline protections to user devices and remote work practices that can affect customer data.
Devices used to access critical systems must have critical updates installed and active antivirus protection. Keeping endpoints current and protected reduces the likelihood of compromise from common threats.
Work devices must use disk encryption, strong passwords, and automatic screen locking after inactivity. These baseline protections help keep stored information and unattended devices secure.
Lost, stolen, or damaged devices must be reported immediately so access can be restricted or revoked. Rapid response helps limit exposure when hardware is no longer under user control.
Endpoints are subject to reviews, audits, and monitoring for compliance, and remote personnel must secure devices and prevent unauthorized viewing or overhearing of customer data. This extends device governance beyond the office environment.
Network security
Protects production networks through controlled access, segmentation, encrypted administration, and external review.
Access to production networks is limited and reviewed on a periodic basis. Tight control over network entry points helps reduce unnecessary exposure to critical environments.
Remote diagnostic and configuration access is limited to dedicated management paths and encrypted application-layer protocols. This helps protect administrative activity from interception or misuse.
Network domains are segregated and data flows between them are controlled through secure gateways. Segmentation reduces the blast radius if one part of the environment is affected.
Relevant network logs are monitored, anomalies are raised as security incidents where applicable, and annual third-party assessments are followed by remediation testing. Ongoing oversight and external validation help confirm that network defenses remain effective.
Privacy and data lifecycle
Supports lawful handling, retention, deletion, and accountability for customer and personal data.
Nebula.io commits to protecting personal data and privacy in line with applicable laws, regulations, and contractual requirements. This supports customer expectations around lawful and responsible data handling.
Retention periods are defined based on classification and applicable obligations, and data is not kept longer than necessary for operational, contractual, or legal purposes. This reduces long-term exposure and supports defensible data management.
Customer or user deletion requests are validated before action is taken, and requests are evaluated for legal and contractual feasibility. Verification helps prevent unauthorized or improper deletion.
When data must be removed, Nebula.io uses secure deletion methods and may anonymize information where permitted, while maintaining logs of deletion requests and actions taken. These practices provide accountability for data lifecycle decisions.
Risk management
Prioritizes security decisions through formal risk assessment, ownership, and treatment.
Nebula.io conducts structured risk assessments that identify threats, quantify likelihood and impact, and document mitigation plans. This helps security efforts focus on the risks most relevant to the business and its customers.
Risk assessments are performed at least annually and updated using lessons from audits and incidents. A regular cadence helps keep the risk picture current as the environment changes.
Risks are assigned to owners, reviewed with management, and evaluated after mitigation for acceptance, transfer, or additional control implementation. Clear ownership improves accountability for risk decisions.
Risk assessments explicitly consider risks introduced by third-party vendors. Including external dependencies helps avoid blind spots in the broader control environment.
Physical and workplace security
Reduces exposure in office and public work settings while keeping production systems outside office premises.
Employees working in public locations are instructed to take precautions against visual eavesdropping and other exposure risks. This helps protect sensitive information in lower-control environments.
Production systems and customer data are hosted with cloud infrastructure providers rather than on office premises, relying on provider physical security controls. This reduces dependence on office facilities for protecting customer environments.
Sensitive customer data, passwords, and security keys are not left exposed, and printing classified customer data is prohibited. These practices help prevent accidental disclosure in shared spaces.
Documentation
Certifications
Security
Policies
Privacy & Legal
Other












No updates available