Compliance & Security posture
How Nexmetry aligns to SOC 2, HIPAA, GDPR, and ISO 27001 — and what that means per tier.
4 min read
Aligned, not a substitute for your own assessment
Nexmetry is built to these frameworks’ controls; “aligned” is not the same as a third-party certification. Formal attestations apply only where explicitly contracted for a hosted Enterprise deployment. Open-source / self-hosted deployments inherit the controls but carry no certification from Nexmetry.
- Designed to SOC 2 (Security/Availability/Confidentiality) control criteria
- HIPAA-aligned handling; BAAs available for hosted Enterprise
- GDPR-aligned by default: region-scoped storage, right to erasure, DPAs
- Hosted on ISO 27001-certified infrastructure partners
- Encryption: AES-256 at rest, TLS 1.3 in transit
