Healthcare data demands evidence, not logos. This page explains what each certification and compliance commitment on our site means, how we protect this website, and how customers and prospects can obtain the underlying documents.
Our controls for protecting customer data are assessed against the AICPA Trust Services Criteria in a SOC 2 examination by an independent auditor.
Evidence: the SOC 2 report, shared with customers and prospects under a non-disclosure agreement.
We process the personal data of people in the European Union in line with the EU General Data Protection Regulation (Regulation (EU) 2016/679).
Evidence: our Privacy Policy, and a Data Processing Agreement (DPA) for customers on request.
We comply with the Personal Data Protection Laws that govern our operations in the Gulf, including the handling of personal data, data subject rights and cross-border transfers.
Evidence: our Privacy Policy, and contractual commitments for customers on request.
Information security management system.
Quality management system.
Business continuity management system.
Environmental management system.
Occupational health and safety management system.
Our risk management follows the ISO 31000 guidelines. ISO 31000 is a guidance standard and is not itself certified.
Certificate details — certification body, certificate number, scope and validity — are available on request.
Ask through our contact form or your NANO account manager.
Tell us what your review requires and we will send the documents that answer it.