Skip to content
Nomisly

Security

Security and trust

Nomisly isolates every business's data at the database level with Postgres row-level security, encrypts secrets at rest, supports Google sign-in and two-step verification, verifies every webhook signature, keeps an append-only audit log and redacts personal data from application logs. We follow OWASP ASVS Level 2 as our baseline.

Tenant isolation

  • Every table with customer data is protected by Postgres row-level security; a request authenticated for one business can't read another's rows even if application code has a bug. Automated tests prove it on every change.
  • Application-level tenant filters and "not found" responses for other tenants' IDs provide a second layer.

Accounts and access

  • Sign in with Google or Microsoft, or e-mail and password with verification; passwords hashed with Argon2id.
  • TOTP two-step verification with single-use recovery codes.
  • Five roles (Owner, Admin, Manager, Agent, Read-only) enforced on the server for every request.
  • Rate limits per IP, user and business; bot protection on sign-up.

Data protection

  • TLS everywhere; strict security headers and content security policy.
  • Integration tokens and API keys encrypted at rest.
  • Personal data (phones, e-mails, tokens) redacted from application logs and error reports.
  • Append-only audit log of sign-ins, exports, deletions, settings changes and staff access.
  • Daily backups with a tested restore procedure.

Integrations

  • Meta webhooks are verified with the X-Hub-Signature-256 HMAC; every inbound event is de-duplicated with an idempotency key.
  • Outbound webhooks are signed; destination URLs pointing at private networks are blocked (SSRF protection), including website crawling for the knowledge base.

AI safety

  • Assistants answer only from each business's own knowledge and hand over when unsure.
  • Documents and customer messages are treated as data, never as instructions (prompt-injection defence).
  • AI disclosure is shown to end users; every AI reply is logged with its sources.

Compliance posture

We design for GDPR, India's DPDP Act 2023, the UAE PDPL, CCPA/CPRA, CASL and LGPD, provide a DPA and publish our sub-processors. We do not currently sign HIPAA BAAs; US healthcare providers must not store PHI in Nomisly. We don't claim certifications we don't hold.

Report a vulnerability

E-mail security@nomisly.com. We acknowledge within 3 business days and won't pursue good-faith research that respects user privacy.

Never miss a lead again

No card needed · Cancel anytime · Setup in under 30 minutes