Naboo · Trust Center

Naboo Trust Center

Trust center

Naboo maintains a public trust center documenting SOC 2 Type II, ISO 27001:2022, GDPR, HIPAA, and Penetration Testing compliance.

CompanyArtificial IntelligenceAI AgentsKnowledge GraphReasoning LayerGraphQLMCPEnterprise SoftwareDeveloper InfrastructureRAG
Trust center: https://www.naboo.ai/security/

Certifications & Compliance

SOC 2 Type IIISO 27001:2022GDPRHIPAAPenetration Testing

Source

Trust Center

naboo-trust-center.yml Raw ↑
generated: '2026-07-20'
method: searched
probe: false
source: https://www.naboo.ai/security/
url: https://www.naboo.ai/security/
summary: >-
  Naboo publishes a Security & Trust page describing its compliance posture,
  data-protection controls, and deployment models. Certifications are largely
  in-progress/roadmap; a program (GDPR, HIPAA BAA, annual pen testing) is
  established with supporting documents (SOC 2 letter of engagement, controls
  matrix, pen-test summary, DPA/BAA) available under NDA.
certifications:
  - name: SOC 2 Type II
    status: in-progress
    detail: Audit window underway; letter of engagement available on request under NDA.
  - name: ISO 27001:2022
    status: roadmap
    detail: Implementation targeted H2 2026.
  - name: GDPR
    status: compliant
    detail: Naboo operates as data processor; customer is controller. DPA available.
  - name: HIPAA
    status: baa-available
    detail: BAA executed per customer engagement; healthcare customers deploy air-gapped or VPC by default.
  - name: Penetration Testing
    status: annual
    detail: Third-party independent testing; latest report available under NDA.
controls:
  encryption_in_transit: TLS 1.3 for all inter-component connections
  encryption_at_rest: AES-256
  kms: [AWS KMS, GCP KMS, Azure Key Vault, HashiCorp Vault]
  rbac: Permissions mirrored from source systems (GitHub teams, Jira projects, Slack channels, Confluence spaces) and enforced at every graph traversal, at retrieval time.
  audit_logging: Per-query audit logging shipped to customer SIEM; customer-controlled retention.
  tenant_isolation: Each deployment runs in the customer environment with separate keys, data, and audit trail.
  no_model_training: Customer data is never used to improve any model.
deployment_models:
  - on-premises
  - customer-vpc
  - air-gapped
security_contact: security@naboo.ai
documents_under_nda:
  - SOC 2 letter of engagement
  - controls matrix
  - pen-test summary
  - sample DPA/BAA
  - incident-response runbook

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/naboo-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.