Legal / Security

Information Security Policy

Last updated: 19 August 2026 · Nuvid AI AB · Org.nr 556945‑6709
Draft for review. This document is a template to start from. Have legal counsel review and adapt it to your actual operations, systems and sub-processors before publishing.

Nuvid AI AB builds and operates technical platforms for the private and public sector. Information security is an integral part of how we develop and deliver our services.

1Management system

Our work is carried out under a management system based on the principles of ISO/IEC 27001, with a risk-based and continuous improvement approach.

2Core principles

3Access control

Access is granted on a need-to-know basis (least privilege) and protected with strong authentication. Permissions are reviewed regularly.

4Encryption

Communication is encrypted with TLS ≥ 1.3. Sensitive data is protected at rest where appropriate. Authentication uses certificates signed with SHA-256 or better.

5Hosting and data storage

The services run with established cloud providers, with data within the EU/EEA, using segmentation, hardening and continuous monitoring.

6Incident management

We have procedures to detect, manage and remediate incidents. For incidents involving personal data, affected customers are notified without undue delay.

7Continuity and backups

We back up data and maintain recovery procedures to sustain operations.

8Supplier management

Suppliers and sub-processors are evaluated from a security and data protection perspective and bound by agreements with equivalent requirements.

9Staff and awareness

Employees are subject to confidentiality and receive ongoing guidance on secure working practices.

10Contact

Questions about information security, or to report a suspected vulnerability, can be sent to hello@nuvid.ai.