search
location
Request a Demo

Trust & Compliance

Healthcare data demands evidence, not logos. This page explains what each certification and compliance commitment on our site means, how we protect this website, and how customers and prospects can obtain the underlying documents.

Data protection and security compliance

SOC 2

Our controls for protecting customer data are assessed against the AICPA Trust Services Criteria in a SOC 2 examination by an independent auditor.

Evidence: the SOC 2 report, shared with customers and prospects under a non-disclosure agreement.

GDPR

We process the personal data of people in the European Union in line with the EU General Data Protection Regulation (Regulation (EU) 2016/679).

Evidence: our Privacy Policy, and a Data Processing Agreement (DPA) for customers on request.

PDPL

We comply with the Personal Data Protection Laws that govern our operations in the Gulf, including the handling of personal data, data subject rights and cross-border transfers.

Evidence: our Privacy Policy, and contractual commitments for customers on request.

ISO management systems

ISO/IEC 27001

Information security management system.

ISO 9001

Quality management system.

ISO 22301

Business continuity management system.

ISO 14001

Environmental management system.

ISO 45001

Occupational health and safety management system.

ISO 31000

Our risk management follows the ISO 31000 guidelines. ISO 31000 is a guidance standard and is not itself certified.

Certificate details — certification body, certificate number, scope and validity — are available on request.

How we protect this website

  • Served only over HTTPS, with HTTP Strict Transport Security.
  • An enforced Content Security Policy that restricts which scripts and connections a page may use.
  • Bot protection on every form, without image puzzles.
  • No analytics or advertising cookies until you accept them — and rejecting is one click. Cookie details.
  • Enquiries and job applications are visible only to the staff who handle them, are not publicly accessible, and are kept for no longer than 24 months.

Documents available on request

  • SOC 2 report (under a non-disclosure agreement)
  • ISO certificates
  • Data Processing Agreement (DPA)
  • Responses to security and privacy questionnaires

Ask through our contact form or your NANO account manager.

Need something for a procurement or security review?

Tell us what your review requires and we will send the documents that answer it.