The most secure data is data that never leaves the device

Nodra's security model starts before encryption: unnecessary information is deleted at the source, so the backend only ever holds what analysis requires.

Encrypted everywhere

TLS in transit, encryption at rest, application-level encryption for sensitive datasets, per-tenant keys stored apart from data.

Isolated per customer

Logical isolation with cross-tenant access prevented by design on Standard. Dedicated single-tenant environments on Private and Enterprise.

Least-privilege access

Named admin accounts, MFA, separation between who runs servers and who analyzes processes, audit logs on sensitive operations.

Backup that restores

Machine and data backups with tested restore procedures. Immutable WORM backup and disaster recovery available on Enterprise.

Configurable retention

Every audit has a lifecycle: collection, processing, verification, deletion of raw data. Timing is agreed and documented.

Incident response

Defined severity levels, escalation paths and communication duties, so a bad day is handled by procedure, not improvisation.

Security is a chain, and we show the whole chain

Every layer has an explicit owner. That honesty is what security reviews want to see, and it is how responsibility actually works.

Data minimizationNodra agent, on the device
PseudonymizationNodra agent, on the device
TLS in transitNodraTech
Authentication and tenant isolationNodraTech
Encryption at rest and per-tenant keysNodraTech
Least privilege, MFA, audit loggingNodraTech operations
Facility, hardware, hypervisorEU cloud provider
Legal basis and employee processCustomer, with advisors

Bring your security questionnaire.

Enterprise deployments include a documentation pack built for vendor assessments. Ask us anything on the call.

Frequently asked questions

Is workflow data encrypted?

Yes. Data is encrypted in transit with TLS and encrypted at rest, with additional application-level encryption for sensitive datasets. Each tenant has distinct encryption keys, and keys are stored separately from the data they protect.

Who can access our data?

Access follows least privilege: named accounts, MFA, role separation between infrastructure operation and process analysis, and audit logs on sensitive access. Nobody gets more access than their role requires.

What happens if something breaks?

Our infrastructure keeps both machine-level and data-level backups with tested restore procedures. Enterprise deployments can add immutable WORM backup, secondary replicas and disaster recovery with agreed RPO and RTO.

What happens when we leave?

Offboarding is a defined procedure: ingestion stops, agreed data is exported, keys and production data are deleted, backups expire per retention, and you receive evidence of deletion. On Private and Enterprise this is a formal deliverable.

Is Nodra 100 percent secure?

No system is, and we will not claim it. What we commit to is layered, verifiable security: minimization so less data exists, encryption and isolation so it is protected, and tested procedures for backup, restore and incidents.