# Nansys Security & Compliance

> Nansys is SOC 2 Type II attested, ISO/IEC 27001:2022 certified, and GDPR compliant. See how we protect incentive, commission, and rebate data.

- HTML: https://nansysinc.com/security
- Markdown: https://nansysinc.com/security.md

Nansys is independently reviewed against the standards enterprise buyers ask for first: SOC 2 Type II, ISO 27001, and GDPR.

## Frameworks

### SOC 2 Type II

Independently attested. An independent auditor examined Nansys controls for security, availability, and confidentiality over an operating period. The SOC 2 Type II report is available to customers and prospects under NDA.

### ISO/IEC 27001:2022

Certified. Nansys maintains a certified Information Security Management System. ISO 27001 is the international standard for how we identify risk, run security controls, and keep improving them.

### GDPR

Compliant. Nansys processes personal data in line with the EU General Data Protection Regulation. Customers can execute the Data Processing Agreement, and the privacy program is continuously monitored.

## Practices

- Encryption: customer data is encrypted in transit and at rest, governed by our encryption and key-management policy
- Access control: role-based access with segregation of duties. Access is granted from data classification and revoked when it is no longer needed
- Formal ISMS: a documented Information Security Management System aligned with ISO 27001:2022 and SOC 2 requirements
- Incident response: a formal process so security incidents are reported, investigated, and handled promptly
- Continuity: business continuity and disaster recovery plans are defined, implemented, and tested
- Ongoing review: regular risk assessments, audits, employee security training, and continuous improvement

## Documents

- [Privacy Policy](https://nansysinc.com/privacy-policy): how we collect, use, store, and protect personal data
- [Data Processing Agreement](https://nansysinc.com/data-processing-contract): contractual GDPR terms for customers who use Nansys as a processor
- [Cookie Policy](https://nansysinc.com/cookie-policy): cookies and similar technologies used on our website
- [SOC 2 Type II report](https://nansysinc.com/contact): available to customers and prospects under NDA

## FAQ

### Is Nansys SOC 2 certified?

SOC 2 is an attestation, not a certification. Nansys has completed a SOC 2 Type II examination — an independent auditor reviewed our controls over a period of time. We share the report with customers and prospects under NDA.

### What does ISO 27001 certification cover?

ISO/IEC 27001:2022 confirms that Nansys runs a certified Information Security Management System. It covers how we assess risk, implement controls, train people, and continually improve security — not a one-time checklist.

### Are you GDPR certified?

GDPR is a regulation, not a certificate you hang on the wall. Nansys is GDPR compliant: we honor data-subject rights, offer a Data Processing Agreement, use Standard Contractual Clauses where required, and monitor our privacy program continuously.

### How do I get security documents for a vendor review?

Use the contact form and mention a security or procurement review. We can share the SOC 2 Type II report under NDA, along with our Privacy Policy and Data Processing Agreement.
