Your first $5 becomes $15Get started
Trust Center

The trust center your procurement team will ask for

Current posture, framework status, and every legal document: one page, honestly labeled. We say exactly what is available today and what is still in progress. No vendor-questionnaire roulette.

trust · posture · contract

Current trust posture

RLS-protected tables100%
USING (true) policies0
Master-key surfaceisolated
SOC 2 (NemoRouter-level)in progress
DPA / SCCs / AUPpublished
Questionnaire turnaround1 business day
TLS 1.3AES-256GDPRHIPAA-eligible
RLS-protected tables
100%

Tenant isolation enforced at the database

Uptime SLA
99.9%

Backed by managed Cloud Run + Supabase

Doc turnaround
1 day

DPA, SCCs, questionnaires: one business day

Customer LLM auth
0 master

Virtual keys only. Never the master key

Posture

Where every framework stands, right now

Status drawn from one source of truth and never overstated: active, in progress, or available on request. We will never put a badge on a framework we have not earned.

  • In progress· Q3 2026

    SOC 2 Type II

    NemoRouter operates SOC 2-aligned security, availability, and confidentiality controls today — encryption, access control, change management, audit logging, tenant isolation.

  • In progress

    ISO/IEC 27001

    Information security management practices aligned to ISO/IEC 27001 Annex A controls — asset management, access control, cryptography, operations security, supplier relationships.

  • Active

    GDPR

    Compliant with the EU General Data Protection Regulation.

  • Available

    HIPAA

    NemoRouter supports HIPAA-eligible workloads.

  • Available

    PCI DSS

    NemoRouter never touches raw cardholder data.

  • Active

    Data residency

    Pin where customer data is processed and stored.

On the record: a formal NemoRouter-level SOC 2 Type II audit is in progress — not complete, and we do not market a certificate we have not earned. The infrastructure we run on (Google Cloud Run, Supabase) is independently SOC 2 Type II and ISO 27001 certified today.

Documents

Available right now, no gate

Linked directly: open them, send them to your auditor, attach them to a ticket. Nothing here requires a sales call.

On request — sent within one business day
Security questionnaire response
Send your CAIQ, SIG, or custom questionnaire. We complete it manually and return it within one business day.
Controls walkthrough
A 30-minute call where your security team and auditor get the same answers we give our engineers.
Business Associate Agreement (BAA)
For organizations processing PHI on an Enterprise plan. Reviewed and signed within 5 business days.
Custom MSA & security exhibit
When procurement needs paper on their template, our legal team works from yours.

We complete security questionnaires manually. No portal in the loop. Every answer is reviewed by the engineer who owns the control. Start the request from the contact page.

Get in touch

Talk to the team that owns the controls

Report a vulnerability, request documentation, or book a controls walkthrough. Security reports are acknowledged in < 48 hours.

FAQ

Common procurement questions

Is NemoRouter SOC 2 certified?

Not yet. And we will not claim otherwise. NemoRouter implements SOC 2-aligned controls today: encryption, access control, audit logging, change management, and tenant isolation, enforced continuously by tests and Row-Level Security rather than periodic audit cycles. Our underlying infrastructure (Google Cloud Run, Supabase) is independently SOC 2 Type II certified. A formal NemoRouter-level SOC 2 Type II audit is on our roadmap; until it completes, Enterprise customers who need a formal report can request a controls walkthrough or a completed vendor questionnaire from security@nemorouter.ai.

How do I get a DPA, SCCs, or your subprocessor list?

The DPA, SCCs, AUP, and subprocessor list are published and linked directly from this page. No gate, no sales call. A pre-signed copy of the DPA is available within one business day if your procurement process needs an executed document.

Can you complete our security questionnaire?

Yes. Email your CAIQ, SIG, or a custom questionnaire to security@nemorouter.ai. We complete it manually and return it within one business day. We do not use an automated questionnaire portal. Every answer is reviewed by the engineering team that owns the control.

Where is customer data stored, and can I pin a region?

Customer data lives in managed Postgres (Supabase) with at-rest encryption, replicated within a single region. We default to US (Cloud Run us-central1). EU residency (europe-west4) is available for residency-sensitive workloads on Enterprise — EU traffic never crosses the Atlantic, and subprocessors are signed under EU SCCs.

What happens if a virtual key leaks?

Virtual keys are tenant-scoped, rate-limited, budget-capped, and observable. Revocation is immediate from the dashboard or API, and cache invalidation propagates within seconds. Keys are hashed in the database. The plaintext is shown exactly once. The blast radius of a leak is the budget on that single key, not your account.

How do I report a security vulnerability?

Email security@nemorouter.ai with details. We acknowledge in < 48 hours, target 7 days for critical fixes, and follow coordinated disclosure — crediting reporters in our changelog when permitted.

Something not covered? Ask us directly from the contact page.

Security review · 30 minutes

Bring your auditor — they will get the same answers we give the engineers

No NDA to start, no sales gate. Send your questionnaire, book a controls walkthrough, or request a signed DPA.