Naboo · Trust Center

Naboo Trust Center

Trust center

Naboo maintains a public trust center documenting SOC 2 Type II, ISO 27001:2022, GDPR, HIPAA, and Penetration Testing compliance.

CompanyArtificial IntelligenceAI AgentsKnowledge GraphReasoning LayerGraphQLModel Context ProtocolEnterprise SoftwareDeveloper InfrastructureRAG
Trust center: https://www.naboo.ai/security/

Certifications & Compliance

SOC 2 Type IIISO 27001:2022GDPRHIPAAPenetration Testing

Source

Trust Center

naboo-trust-center.yml Raw ↑
generated: '2026-07-20'
method: searched
probe: false
source: https://www.naboo.ai/security/
url: https://www.naboo.ai/security/
summary: >-
  Naboo publishes a Security & Trust page describing its compliance posture,
  data-protection controls, and deployment models. Certifications are largely
  in-progress/roadmap; a program (GDPR, HIPAA BAA, annual pen testing) is
  established with supporting documents (SOC 2 letter of engagement, controls
  matrix, pen-test summary, DPA/BAA) available under NDA.
certifications:
  - name: SOC 2 Type II
    status: in-progress
    detail: Audit window underway; letter of engagement available on request under NDA.
  - name: ISO 27001:2022
    status: roadmap
    detail: Implementation targeted H2 2026.
  - name: GDPR
    status: compliant
    detail: Naboo operates as data processor; customer is controller. DPA available.
  - name: HIPAA
    status: baa-available
    detail: BAA executed per customer engagement; healthcare customers deploy air-gapped or VPC by default.
  - name: Penetration Testing
    status: annual
    detail: Third-party independent testing; latest report available under NDA.
controls:
  encryption_in_transit: TLS 1.3 for all inter-component connections
  encryption_at_rest: AES-256
  kms: [AWS KMS, GCP KMS, Azure Key Vault, HashiCorp Vault]
  rbac: Permissions mirrored from source systems (GitHub teams, Jira projects, Slack channels, Confluence spaces) and enforced at every graph traversal, at retrieval time.
  audit_logging: Per-query audit logging shipped to customer SIEM; customer-controlled retention.
  tenant_isolation: Each deployment runs in the customer environment with separate keys, data, and audit trail.
  no_model_training: Customer data is never used to improve any model.
deployment_models:
  - on-premises
  - customer-vpc
  - air-gapped
security_contact: security@naboo.ai
documents_under_nda:
  - SOC 2 letter of engagement
  - controls matrix
  - pen-test summary
  - sample DPA/BAA
  - incident-response runbook