Security & Compliance

Built to protect your incentive data

Nansys is independently reviewed against the standards enterprise buyers ask for first: SOC 2 Type II, ISO 27001, and GDPR.

  • AICPA SOC for Service Organizations
  • ISO 27001 certified, monitored on Scrut
  • GDPR compliant, monitored on Scrut
Independent review

The standards we meet

Named frameworks, not generic lock icons. Each badge below is backed by an audit, a certificate, or a documented privacy program.

AICPA SOC for Service Organizations

Independently attested

SOC 2 Type II

An independent auditor examined Nansys controls for security, availability, and confidentiality over an operating period. The SOC 2 Type II report is available to customers and prospects under NDA.

ISO 27001 certified, monitored on Scrut

Certified

ISO/IEC 27001:2022

Nansys maintains a certified Information Security Management System. ISO 27001 is the international standard for how we identify risk, run security controls, and keep improving them.

GDPR compliant, monitored on Scrut

Compliant

GDPR

We process personal data in line with the EU General Data Protection Regulation. Customers can execute our Data Processing Agreement, and our privacy program is continuously monitored.

Why it matters

What this means for your team

Security reviews should not stall a commission or rebate project. These programs give procurement and InfoSec a clear starting point.

Faster vendor reviews

Share a current SOC 2 Type II report and ISO 27001 certificate instead of starting every questionnaire from a blank page.

Enterprise procurement ready

The same controls your security team already asks about — access, encryption, incident response, continuity — are independently reviewed.

Clear data-protection terms

A published Privacy Policy and Data Processing Agreement so legal and privacy teams can review how Nansys handles personal data.

How we protect data

Security practices behind the badges

Drawn from the same controls described in our Privacy Policy and Data Processing Agreement.

Encryption

Customer data is encrypted in transit and at rest, governed by our encryption and key-management policy.

Access control

Role-based access with segregation of duties. Access is granted from data classification and revoked when it is no longer needed.

Formal ISMS

A documented Information Security Management System aligned with ISO 27001:2022 and SOC 2 requirements.

Incident response

A formal process so security incidents are reported, investigated, and handled promptly.

Continuity

Business continuity and disaster recovery plans are defined, implemented, and tested so systems stay available.

Ongoing review

Regular risk assessments, audits, employee security training, and continuous improvement of our security posture.

Questions

Common security questions

Is Nansys SOC 2 certified?

SOC 2 is an attestation, not a certification. Nansys has completed a SOC 2 Type II examination — an independent auditor reviewed our controls over a period of time. We share the report with customers and prospects under NDA.

What does ISO 27001 certification cover?

ISO/IEC 27001:2022 confirms that Nansys runs a certified Information Security Management System. It covers how we assess risk, implement controls, train people, and continually improve security — not a one-time checklist.

Are you GDPR certified?

GDPR is a regulation, not a certificate you hang on the wall. Nansys is GDPR compliant: we honor data-subject rights, offer a Data Processing Agreement, use Standard Contractual Clauses where required, and monitor our privacy program continuously.

How do I get security documents for a vendor review?

Use the contact form and mention a security or procurement review. We can share the SOC 2 Type II report under NDA, along with our Privacy Policy and Data Processing Agreement.

Need the report for a security review?

Tell us you are running a vendor assessment. We will share the SOC 2 Type II report under NDA and walk through any remaining questions.

Get Started

Ready to get every payout right?

Join 500+ companies already using Nansys ICRM to streamline incentive management and improve payout accuracy.

Why teams choose Nansys

Faster onboarding with expert implementation support

Enterprise controls with full auditability

Accurate, transparent payouts at scale