Security

Your contracts are sensitive.
We treat them that way.

Nissa processes confidential contract data. Security isn't an afterthought — it's a core requirement of the platform.

Encryption everywhere

All data encrypted in transit (TLS 1.3) and at rest (AES-256). Contract documents are encrypted at the application level before storage.

Tenant isolation

Each customer's data is logically isolated. Your contract data is never accessible to other customers or used across accounts.

Access controls

Role-based access controls with least-privilege principles. Internal access to customer data is logged and restricted to authorized personnel only.

No training on your data

Your contract data is never used to train machine learning models. AI processing is applied to your documents exclusively to serve you.

Infrastructure

Nissa runs on cloud infrastructure provided by leading providers with SOC 2, ISO 27001, and other industry certifications. Our infrastructure includes:

Application security

Data handling

Organizational security

Compliance

We are committed to meeting the compliance requirements of our customers. Our current compliance posture includes:

Vulnerability disclosure

We welcome responsible disclosure of security vulnerabilities. If you discover a potential security issue, please report it to security@nissa.ai. We commit to:

Questions

For security inquiries, to request our SOC 2 report, or to discuss specific compliance requirements, contact us at:

security@nissa.ai