N Nordic Data

Security at Nordic Data

This page summarises how we secure the platform. Last updated: 2026-05-22.

Vulnerability disclosure program

We welcome responsible disclosure of security vulnerabilities. Email [email protected] with details. We will acknowledge within 24 hours and target a fix within 14 days for confirmed critical or high severity issues.

In scope: nordicdata.cloud, api.nordicdata.cloud, the npm package nordic-data, the MCP server at cloud.nordicdata/nordic-data.

Out of scope: third-party services we link to (Stripe, Zoho, Vultr).

We do not run a paid bug bounty at this time. We will publicly acknowledge submitters with permission in the acknowledgments below.

Controls in place

Data handling

Acknowledgments

No disclosures yet. Researchers acknowledged here with permission once a report is resolved.

SOC 2 / ISO 27001

Nordic Data is not currently SOC 2 audited. We maintain a CONTROLS inventory aligned to the Trust Service Criteria (Security, Availability, Confidentiality). Audit engagement planned for Q3 2026 contingent on first enterprise customer requiring it. For early-access customers needing a Data Processing Agreement, see /legal/dpa. Existing customers: Sign in · Dashboard →

Sub-processors

See /legal/sub-processors.