Skip to content
NESJA.OS

Security & trust

Your commercial data deserves the highest standard of care.

NESJA is designed for organisations that hold sensitive commercial data. This page sets out our security principles, deployment architecture and platform controls, and the real status of every certification on our roadmap.

Principles

How we approach security.

  • Your data is yours

    Customer data belongs to the customer. We process it to deliver NESJA, and nothing else.

  • Least privilege

    Access to customer environments is restricted, justified and reviewed.

  • Transparency over claims

    We publish the status of every certification and control, including those on our roadmap.

  • Built for regulated industries

    Our architecture is designed for dedicated, private and sovereign deployment models.

Architecture

Designed for where your data needs to live.

  • Multi-tenant cloud

    The standard NESJA service, operated by NESJA.

  • Dedicated environment

    An isolated NESJA environment for a single organisation.

  • Private & sovereign cloud

    Deployment within national or customer-controlled cloud environments, for regulated sectors.

The deployment model for your organisation is agreed as part of your proposal.

Platform controls

Security and resilience controls.

Encryption, identity, access, audit, backup, recovery, residency and sovereign hosting, with the current status of each.

  • Encryption

    Encryption of customer data in transit and at rest.

    Planned
  • Single sign-on (SSO)

    Sign in through your corporate identity provider.

    Planned
  • Multi-factor authentication

    A second factor for every user sign-in.

    Planned
  • Role-based access control

    Permissions scoped by role, team and record.

    Planned
  • Audit trails

    A record of who changed what, and when.

    Planned
  • Backups

    Regular, tested backups of customer data.

    Planned
  • Disaster recovery

    Documented recovery objectives and procedures.

    Planned
  • Data residency

    Choice of hosting region for customer data.

    Planned
  • Sovereign hosting

    Deployment within national or sovereign cloud environments for regulated organisations.

    Planned

Certifications & compliance

Certification roadmap.

We list each certification with its real status: Achieved, In progress or Planned. Nothing is shown as achieved until it has been independently confirmed.

  • ISO/IEC 27001

    Information security management system certification.

    Planned
  • SOC 2 Type II

    Independent attestation of security, availability and confidentiality controls.

    Planned
  • GDPR alignment

    Data-protection practices aligned with the EU General Data Protection Regulation.

    Planned

Security reviews

Request security information.

Tell us what your security and procurement review requires. We'll respond with the information that applies to your deployment.

Request Security Information