Trust Center
How Nubesti treats authorization, data, and platform security.
This page is the public index for security, privacy, and responsible offensive-testing controls. It links to binding legal documents. It does not claim certifications Nubesti does not hold.
Security
Production marketing and application traffic is served over TLS through Cloudflare. Legal documents describe encryption in transit, encryption at rest where we control the store, unique administrative identities with MFA, role-based access in the product, and security-relevant logging.
Details that belong in a CISO review: Platform security. Binding language: Security overview.
Privacy
Account, billing, website, and support data are handled as described in the Privacy Policy. When we process customer personal data as a processor, the DPA applies. Current subprocessors: Subprocessors. Cookie use: Cookie Policy.
Privacy requests: [email protected] ยท [email protected].
Responsible security
Report vulnerabilities in Nubesti systems (not customer targets) under the Vulnerability Disclosure Policy. Email [email protected]. Canonical researcher file: /.well-known/security.txt.
Offensive-security safety
Paid access and test launches require KYC. Tests run only against assets the customer authorizes and owns or has written permission to test. Rules of Engagement, an authorization letter, and an acceptable-use policy apply. You can stop in-progress jobs from the portal.
See KYC, Authorization, Rules of Engagement, and Acceptable Use.
Compliance posture
Nubesti is not presenting SOC 2, ISO 27001, PCI DSS, HIPAA, or FedRAMP as current certifications. Controls are described in legal documents so customers can map them to their programs. Formal reports, if they exist later, will be stated exactly and dated.
Talk to Security
Architecture reviews, platform incidents, abuse of tests.
[email protected]
Talk to Sales
Plans, KYC onboarding, and a live walkthrough.
Book a meeting
Report a Vulnerability
Issues in Nubesti systems only โ not customer targets.
Disclosure policy
Privacy request
Access, deletion, DPA questions.
[email protected]
Legal
Contracts, authorization letters, notices.
[email protected]