Security by Design
At NevTan Cloud, security is a foundational principle built into every layer of our platform. Businesses entrust us with critical applications, data, and infrastructure. Our responsibility is to provide a secure, resilient, and reliable environment so customers can operate with confidence.
Infrastructure Security
Data Security
| Layer | Control | Standard |
|---|---|---|
| Data at rest | Full-volume encryption | AES-256 |
| Data in transit | Transport layer encryption | TLS 1.2+ |
| Database backups | Encrypted identical to primary | AES-256 |
| Key management | Secure KMS + rotation policy | BYOK on Enterprise |
Access Controls
- Least-privilege access — all production access is explicitly authorized, time-limited, and fully logged
- MFA required for all NevTan Cloud staff on production systems; strongly recommended for customers
- Role-based access control (RBAC) lets customers assign precise permissions per team member
- API keys scoped to specific resources and capabilities, revocable at any time
Vulnerability Management
We conduct regular vulnerability assessments and penetration testing. Security patches for critical vulnerabilities are applied on an accelerated timeline. We welcome responsible disclosure at security@nevtan.com — please allow reasonable remediation time before public disclosure.
Incident Response
NevTan Cloud maintains a documented incident response plan covering detection, containment, eradication, recovery, and post-incident review. Customers affected by a security incident are notified within 72 hours of our becoming aware, in accordance with applicable law.
Compliance Posture
| Standard / Regulation | Status | Notes |
|---|---|---|
| GDPR | Compliant | DPA available on request |
| CCPA | Compliant | Privacy rights fully supported |
| SOC 2 Type II | In progress | Audit underway |
| ISO 27001 | In progress | Certification in progress |
Report a Vulnerability
Contact our security team at security@nevtan.com. We follow responsible disclosure principles and aim to acknowledge reports within 24 hours. Our full Trust Center has additional controls, certifications, and compliance documents.
We're here to help
Our team responds to legal and policy questions within one business day.