Built to protect your incentive data
Nansys is independently reviewed against the standards enterprise buyers ask for first: SOC 2 Type II, ISO 27001, and GDPR.
The standards we meet
Named frameworks, not generic lock icons. Each badge below is backed by an audit, a certificate, or a documented privacy program.

Independently attested
SOC 2 Type II
An independent auditor examined Nansys controls for security, availability, and confidentiality over an operating period. The SOC 2 Type II report is available to customers and prospects under NDA.

Certified
ISO/IEC 27001:2022
Nansys maintains a certified Information Security Management System. ISO 27001 is the international standard for how we identify risk, run security controls, and keep improving them.

Compliant
GDPR
We process personal data in line with the EU General Data Protection Regulation. Customers can execute our Data Processing Agreement, and our privacy program is continuously monitored.
What this means for your team
Security reviews should not stall a commission or rebate project. These programs give procurement and InfoSec a clear starting point.
Faster vendor reviews
Share a current SOC 2 Type II report and ISO 27001 certificate instead of starting every questionnaire from a blank page.
Enterprise procurement ready
The same controls your security team already asks about — access, encryption, incident response, continuity — are independently reviewed.
Clear data-protection terms
A published Privacy Policy and Data Processing Agreement so legal and privacy teams can review how Nansys handles personal data.
Security practices behind the badges
Drawn from the same controls described in our Privacy Policy and Data Processing Agreement.
Encryption
Customer data is encrypted in transit and at rest, governed by our encryption and key-management policy.
Access control
Role-based access with segregation of duties. Access is granted from data classification and revoked when it is no longer needed.
Formal ISMS
A documented Information Security Management System aligned with ISO 27001:2022 and SOC 2 requirements.
Incident response
A formal process so security incidents are reported, investigated, and handled promptly.
Continuity
Business continuity and disaster recovery plans are defined, implemented, and tested so systems stay available.
Ongoing review
Regular risk assessments, audits, employee security training, and continuous improvement of our security posture.
Policies and reports
Self-serve policies are public. Audit reports are shared with customers and prospects under NDA.
Privacy Policy
How we collect, use, store, and protect personal data.
Data Processing Agreement
Contractual GDPR terms for customers who use Nansys as a processor.
Cookie Policy
Cookies and similar technologies used on our website.
SOC 2 Type II report
Available to customers and prospects under NDA. Request it from our team.
Common security questions
Is Nansys SOC 2 certified?
SOC 2 is an attestation, not a certification. Nansys has completed a SOC 2 Type II examination — an independent auditor reviewed our controls over a period of time. We share the report with customers and prospects under NDA.
What does ISO 27001 certification cover?
ISO/IEC 27001:2022 confirms that Nansys runs a certified Information Security Management System. It covers how we assess risk, implement controls, train people, and continually improve security — not a one-time checklist.
Are you GDPR certified?
GDPR is a regulation, not a certificate you hang on the wall. Nansys is GDPR compliant: we honor data-subject rights, offer a Data Processing Agreement, use Standard Contractual Clauses where required, and monitor our privacy program continuously.
How do I get security documents for a vendor review?
Use the contact form and mention a security or procurement review. We can share the SOC 2 Type II report under NDA, along with our Privacy Policy and Data Processing Agreement.
Need the report for a security review?
Tell us you are running a vendor assessment. We will share the SOC 2 Type II report under NDA and walk through any remaining questions.