Nuvid AI AB builds and operates technical platforms for the private and public sector. Information security is an integral part of how we develop and deliver our services.
Our work is carried out under a management system based on the principles of ISO/IEC 27001, with a risk-based and continuous improvement approach.
Access is granted on a need-to-know basis (least privilege) and protected with strong authentication. Permissions are reviewed regularly.
Communication is encrypted with TLS ≥ 1.3. Sensitive data is protected at rest where appropriate. Authentication uses certificates signed with SHA-256 or better.
The services run with established cloud providers, with data within the EU/EEA, using segmentation, hardening and continuous monitoring.
We have procedures to detect, manage and remediate incidents. For incidents involving personal data, affected customers are notified without undue delay.
We back up data and maintain recovery procedures to sustain operations.
Suppliers and sub-processors are evaluated from a security and data protection perspective and bound by agreements with equivalent requirements.
Employees are subject to confidentiality and receive ongoing guidance on secure working practices.
Questions about information security, or to report a suspected vulnerability, can be sent to hello@nuvid.ai.