Security & trust
Your commercial data deserves the highest standard of care.
NESJA is designed for organisations that hold sensitive commercial data. This page sets out our security principles, deployment architecture and platform controls, and the real status of every certification on our roadmap.
Principles
How we approach security.
Your data is yours
Customer data belongs to the customer. We process it to deliver NESJA, and nothing else.
Least privilege
Access to customer environments is restricted, justified and reviewed.
Transparency over claims
We publish the status of every certification and control, including those on our roadmap.
Built for regulated industries
Our architecture is designed for dedicated, private and sovereign deployment models.
Architecture
Designed for where your data needs to live.
Multi-tenant cloud
The standard NESJA service, operated by NESJA.
Dedicated environment
An isolated NESJA environment for a single organisation.
Private & sovereign cloud
Deployment within national or customer-controlled cloud environments, for regulated sectors.
The deployment model for your organisation is agreed as part of your proposal.
Platform controls
Security and resilience controls.
Encryption, identity, access, audit, backup, recovery, residency and sovereign hosting, with the current status of each.
Encryption
Encryption of customer data in transit and at rest.
PlannedSingle sign-on (SSO)
Sign in through your corporate identity provider.
PlannedMulti-factor authentication
A second factor for every user sign-in.
PlannedRole-based access control
Permissions scoped by role, team and record.
PlannedAudit trails
A record of who changed what, and when.
PlannedBackups
Regular, tested backups of customer data.
PlannedDisaster recovery
Documented recovery objectives and procedures.
PlannedData residency
Choice of hosting region for customer data.
PlannedSovereign hosting
Deployment within national or sovereign cloud environments for regulated organisations.
Planned
Certifications & compliance
Certification roadmap.
We list each certification with its real status: Achieved, In progress or Planned. Nothing is shown as achieved until it has been independently confirmed.
ISO/IEC 27001
Information security management system certification.
PlannedSOC 2 Type II
Independent attestation of security, availability and confidentiality controls.
PlannedGDPR alignment
Data-protection practices aligned with the EU General Data Protection Regulation.
Planned
Security reviews
Request security information.
Tell us what your security and procurement review requires. We'll respond with the information that applies to your deployment.