Nordlet

← Docs / Legal

Security

How Nordlet scans for vulnerabilities, controls access, keeps backups and protects customer data, and how to report a security issue.

Last updated: 2026-10-08

This page describes the security measures Nordlet OÜ applies to the Nordlet website, application and API. The contractual commitments are in the Data Processing Agreement, Annex 2.

1. Hosting

Nordlet runs on three hosting providers: one for the application servers, one for the database, and one for the web application, uploaded files and transactional email. Customer data is stored and processed in the European Union.

Hosting role Certifications held by the provider
Application servers ISO/IEC 27001:2022; HDS (French health data hosting)
Database ISO/IEC 27001; ISO/IEC 27701; SOC 2 Type 1 and Type 2; SOC 3
Web application, file storage and email ISO/IEC 27001, 27017, 27018 and 27701; SOC 1, SOC 2 and SOC 3; PCI DSS; BSI C5

These are certifications of the hosting providers. Nordlet itself holds no security certification.

2. Vulnerability scanning

Every change to the code runs through an automated pipeline. The pipeline:

  • checks every production dependency against the npm advisory database, and fails the build when a dependency has a high or critical advisory;
  • reports moderate and low advisories;
  • scans the SQL in the code for unsafe query patterns;
  • checks the API description against OWASP API security rules;
  • runs the unit, integration and end-to-end tests, including a test that fails when a database table holding company data is not protected by row-level security.

The pipeline runs on every push and every pull request. Third-party build actions are pinned to exact versions.

Target times to fix a vulnerability, counted from when Nordlet learns of it:

Severity Fixed within
Critical 24 hours
High 7 days

3. Software inventory

Every software dependency, direct and indirect, is recorded with its exact version and integrity hash in the repository's lockfile. The test pipeline and the web application build install only what the lockfile lists, and fail if the lockfile does not match the declared dependencies.

4. Access control

  • One person at Nordlet has access to production systems.
  • Production access is reviewed every quarter, and the security policies are reviewed at the same time.
  • Every account Nordlet uses to run the service, including hosting, database, code repository and email accounts, has two-factor authentication.
  • Access is through individual credentials and is limited to what operating the service requires.

5. Authentication of customers

  • Users sign in with a one-time link sent to their email address. The link is valid for 15 minutes and works once. A session lasts 30 days.
  • API clients use API keys. Each key belongs to one company, carries a fixed set of permissions, can have an expiry date and can be revoked.
  • Sign-in links, sessions, invitations and API keys are stored only as SHA-256 hashes, so a copy of the database does not reveal them.
  • Users act in a company through a membership with a role. The role decides what the user can read and change.

6. Tenant isolation

Every database table holding company data carries the company identifier and has row-level security enforced by the database. Each request runs with the company taken from the signed-in session or the API key, never from the request body. A query without a company context returns no rows.

7. Encryption

  • All connections to the website, the application and the API use TLS.
  • Uploaded files are encrypted at rest. The database is stored on encrypted storage.
  • Webhooks sent to customers are signed with HMAC (x-nordlet-signature header).

8. Backups

Backup Retention
Daily database backup Rolling 90 days
Point-in-time restore of the database Any moment in the last 7 days

9. Logging and integrity

  • Posted journal entries cannot be changed; corrections are made with reversing entries.
  • An audit log records who changed what and when in each company.
  • Server and application logs are kept for 90 days.
  • Requests are rate-limited.

10. Incidents

If a personal data breach affects customer data, Nordlet notifies the customer by email to the account owner without undue delay, and at the latest 48 hours after becoming aware of it, as set out in the Data Processing Agreement, section 6.

11. Reporting a security issue

Send security reports to info@nordlet.com. Include the steps to reproduce the issue. Please do not access other customers' data and do not publish the issue before it is fixed.