SECURITY & COMPLIANCE

Enterprise-Grade Security

Your formulations are your competitive advantage. We protect them with OS-enforced sandboxes, encryption, and strict access controls.

🔐

Data Protection

All data encrypted at rest (AES-256) and in transit (TLS 1.3). Supabase with row-level security ensures multi-tenant data isolation. Automatic daily backups with point-in-time recovery.

🛡️

NemoClaw Infrastructure

OS-enforced, per-binary network policy sandboxes. Not application-level filtering — even from inside the sandbox, an unapproved process can't open a socket to an allowed endpoint. 29 isolated sandboxes deployed.

📜

FSMA 204 Ready

Enterprise plans include lot-level traceability, batch documentation, and audit-ready reporting aligned with the FDA's FSMA 204 rule. Compliance deadline: July 2028. We're ready now.

👥

Access Control

SSO via Microsoft Entra ID (Enterprise). Role-based access control per workspace. Audit logs for all data modifications. Multi-tenant isolation with per-organization OAuth.

📦

Data Ownership

Your formulas, trials, specs, and supplier data belong to you. Export anytime via PDF or API. No lock-in. No vendor dependency. Cancel and take your data with you.

📊

SOC 2 Roadmap

SOC 2 Type II certification is on our roadmap as part of Phase 4 (Security). We're committed to third-party validation of our security controls, policies, and procedures.

Questions About Security?

Our team can walk you through our security architecture and compliance capabilities.