SOC2C

Is this your company? Buyers are checking NimbleWork Inc here. Claim nimblework.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
NimbleWork Inc logo

NimbleWork Inc

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

NimbleWork Inc is SOC 2 Type II compliant. NimbleWork Inc also holds ISO 27001, and GDPR.

Framework
Auditor
Last report
Renewal
View official trust center ↗

Compliance & infrastructure

Hosting
AWS

Documents

27

Subprocessors

14
  • A
    Amazon Web Services · Cloud Service Provider
    United States, European Union (SwiftKanban)
  • C
    Cloudflare, Inc. · Content-based firewall, Zero Trust Network Provider
    United States
  • M
    MongoDB Atlas · Data storage and processing
  • V
    Veracode · Security
  • M
    Microsoft Corporation · Microsoft Teams, Microsoft Clarity
    United States
  • G
    Google LLC · Google Workspace, Google Analytics
    United States
  • M
    Mixpanel · Usage Analytics
    United States, European Union
  • S
    Stripe · Payment Management
    United States, India
  • Z
    Zapier · Integration Platform
    United States
  • S
    Snaplogic · Data and Application Integration
  • O
    OpenAI ChatGPT · Collaboration AI Service
    United States
  • G
    GitHub · Version control
Show all 14 subprocessors
  • G
    GitLab · Version control
  • V
    Vanta

Compliance leadership

The person who leads NimbleWork Inc's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. NimbleWork Inc's penetration test vendor isn't listed yet.

Claim this profile to add it.

This listing is partial

6/11 details · 55%

SOC2C shows the verified essentials. 5 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Description
    Add a one-line description so buyers recognize you.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is NimbleWork Inc SOC 2 compliant?
NimbleWork Inc is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is NimbleWork Inc ISO 27001 certified?
According to NimbleWork Inc's public trust center, NimbleWork Inc is ISO 27001 certified. On SOC2C this listing is Listed.
Is NimbleWork Inc GDPR compliant?
According to NimbleWork Inc's public trust center, NimbleWork Inc is GDPR compliant. On SOC2C this listing is Listed.
Is NimbleWork Inc SOC 2 Type I or Type II?
NimbleWork Inc is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use NimbleWork Inc's SOC 2 for a vendor risk assessment?
Yes. NimbleWork Inc's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.

Answers published by NimbleWork Inc

Reproduced from NimbleWork Inc's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

Do the organisation and all subcontractors commissioned to provide the service (e.g., cloud IaaS or PaaS providers) have documented information security processes?
All NimbleWork products and all subcontractors have well-documented information security processes. We prioritise the establishment of robust security practices.
Does the organisation hold a valid certification (ISO 27001:2013 or ISO 27001:2022) of its Information Security Management System?
All NimbleWork products hold valid certification for their ISMS based on ISO 27001:2022. This certification underscores our commitment to information security.
Do all subcontractors hold valid certifications (ISO 27001:2013 or ISO 27001:2022)? Does the scope of the certifications cover the services utilised for the organisation?
All subcontractors engaged by all NimbleWork products must hold valid certifications, either ISO 27001 or SOC 2. The scope of these certifications covers the services utilised for the cloud service to ensure comprehensive security coverage.
At which location(s) do all NimbleWork products store, process and back up the data?
Customer data is hosted within Amazon Web Services (AWS) infrastructure in accordance with our data residency requirements. The primary data centre is located in the US East 1 region, with a secondary backup facility in the US West 2 region. All data storage and processing operations comply with applicable data protection regulations and contractual obligations. Geographic redundancy ensures business continuity while maintaining data sovereignty requirements.
Does all NimbleWork products encrypt data at rest using state-of-the-art encryption?
Yes, all customer data stored in our system is encrypted at rest using industry-standard AES-256 encryption. This encryption is applied at the database and storage levels to protect data from unauthorized access. Encryption keys are managed securely using dedicated key management services with strict access controls and regular rotation policies to maintain the highest level of data security.

Business & Industrial peers that completed SOC 2