Security & data storage

Nisenta is itself a compliance product, so we stick to what we can actually verify about our own operations - no invented certifications.

Where your data is stored

The database and all uploaded files are stored within the EU, in Sweden (Stockholm). The application's server code also runs in Sweden.

Separation between customers

Each customer's data is isolated at the database level (Row Level Security in Postgres) - not just in the application code. A reseller can never see another reseller's customers, and a customer can never see another customer's data. This has been verified through direct tests against the database, not just through the interface.

Two-factor authentication

Every account type - customer, reseller, and admin - can enable two-factor authentication (TOTP) under their security settings.

Encryption

All traffic to and from Nisenta is encrypted in transit (HTTPS/TLS). Data is also encrypted at rest with our database provider.

Backups

The database is backed up automatically on an ongoing basis by our database provider. On top of that, administrators have a manual export function as an extra safety net.

Data Processing Agreement (DPA)

If you need a Data Processing Agreement for your own GDPR documentation, contact us and we'll arrange it.

This page describes how our technical platform is built and operated. It doesn't replace a formal legal assessment of your own compliance - contact us if you have questions.

Frequently asked questionsGet started as a customer