Trust center
Security and privacy, in the open.
Everything your security, legal or procurement team usually asks a vendor for, on one page: what we comply with, how we protect data, who processes it and the agreement we sign.
Get our DPALast updated 7 October 2026Compliance
Compliant with EU, UK and Indian data protection law.
GDPR, the UK GDPR and India's DPDP Act have no certifying body. Compliance is something a company does and documents, and our privacy notice and Data Processing Agreement are that record.
We do not hold a SOC 2 report or an ISO 27001 certificate today. If your procurement process needs one, tell us early and we will walk your team through the controls below in writing.
Security controls
Access
- Multi-factor authentication is on for every core account: Google Workspace, GitHub, Cloudflare and Razorpay.
- Access to client systems is granted per person, limited to what the work needs, and removed when the work ends.
- Everyone who works on client data is bound by a confidentiality agreement.
Your code and accounts
- Code lives in your repositories when you ask for it, and the accounts we set up for you stay yours.
- We never reuse one client's data, code or credentials for another client.
Infrastructure
- Our website is served only over HTTPS, with HSTS and a strict set of security headers.
- Our email domain publishes SPF, DKIM and DMARC records, which help receiving servers reject mail forged in our name.
- Our providers encrypt stored data at rest.
- Our own website sets no tracking cookies and runs no analytics or advertising pixels.
Incidents
- If a personal data breach affects your data, we notify you without undue delay, and within 48 hours of becoming aware of it, as our DPA sets out.
Subprocessors
These providers may process personal data on our behalf. For client work, we only add a new subprocessor after notice, as the DPA describes.
| Provider | Purpose | Location | Used for |
|---|---|---|---|
| Cloudflare | Website hosting, security, email routing | United States (global network) | Client projects and website |
| Google Workspace | Email, documents and file storage | United States | Client projects and website |
| GitHub | Source code hosting, when the client does not host it | United States | Client projects |
| Resend | Sends the free AI check report by email | United States | Website only |
| Calendly | Call scheduling, only if you book a call | United States | Website only |
Documents
- Data Processing Agreement: EU Standard Contractual Clauses and the UK Addendum built in. Open it and print or save it as PDF.
- Privacy notice: how we handle data from this website.
- security.txt: our security contact in the standard format.
Need a security questionnaire filled in? Send it to hello@nactore.com.
Report a vulnerability
If you think you have found a security issue in nactore.com or anything we run, email hello@nactore.com with "Security" in the subject. Include what you found and how to reproduce it. We reply within one business day, and we will not take action against good-faith research that avoids privacy harm and service disruption.