Security
Security and trust
Nomisly isolates every business's data at the database level with Postgres row-level security, encrypts secrets at rest, supports Google sign-in and two-step verification, verifies every webhook signature, keeps an append-only audit log and redacts personal data from application logs. We follow OWASP ASVS Level 2 as our baseline.
Tenant isolation
- Every table with customer data is protected by Postgres row-level security; a request authenticated for one business can't read another's rows even if application code has a bug. Automated tests prove it on every change.
- Application-level tenant filters and "not found" responses for other tenants' IDs provide a second layer.
Accounts and access
- Sign in with Google or Microsoft, or e-mail and password with verification; passwords hashed with Argon2id.
- TOTP two-step verification with single-use recovery codes.
- Five roles (Owner, Admin, Manager, Agent, Read-only) enforced on the server for every request.
- Rate limits per IP, user and business; bot protection on sign-up.
Data protection
- TLS everywhere; strict security headers and content security policy.
- Integration tokens and API keys encrypted at rest.
- Personal data (phones, e-mails, tokens) redacted from application logs and error reports.
- Append-only audit log of sign-ins, exports, deletions, settings changes and staff access.
- Daily backups with a tested restore procedure.
Integrations
- Meta webhooks are verified with the X-Hub-Signature-256 HMAC; every inbound event is de-duplicated with an idempotency key.
- Outbound webhooks are signed; destination URLs pointing at private networks are blocked (SSRF protection), including website crawling for the knowledge base.
AI safety
- Assistants answer only from each business's own knowledge and hand over when unsure.
- Documents and customer messages are treated as data, never as instructions (prompt-injection defence).
- AI disclosure is shown to end users; every AI reply is logged with its sources.
Compliance posture
We design for GDPR, India's DPDP Act 2023, the UAE PDPL, CCPA/CPRA, CASL and LGPD, provide a DPA and publish our sub-processors. We do not currently sign HIPAA BAAs; US healthcare providers must not store PHI in Nomisly. We don't claim certifications we don't hold.
Report a vulnerability
E-mail security@nomisly.com. We acknowledge within 3 business days and won't pursue good-faith research that respects user privacy.
Never miss a lead again
No card needed · Cancel anytime · Setup in under 30 minutes