Compliance & Security posture

How Nexmetry aligns to SOC 2, HIPAA, GDPR, and ISO 27001 — and what that means per tier.

4 min read
Aligned, not a substitute for your own assessment
Nexmetry is built to these frameworks’ controls; “aligned” is not the same as a third-party certification. Formal attestations apply only where explicitly contracted for a hosted Enterprise deployment. Open-source / self-hosted deployments inherit the controls but carry no certification from Nexmetry.
  • Designed to SOC 2 (Security/Availability/Confidentiality) control criteria
  • HIPAA-aligned handling; BAAs available for hosted Enterprise
  • GDPR-aligned by default: region-scoped storage, right to erasure, DPAs
  • Hosted on ISO 27001-certified infrastructure partners
  • Encryption: AES-256 at rest, TLS 1.3 in transit