GDPR compliant. EU hosted. Certified infrastructure.
We sell AI governance, so it would be a poor look to be vague about our own. This page is written to be checked line by line by the person whose job it is to say no.
Version 1.0 · 27 August 2026 · Nomad AI Ltd, registered in Ireland
GDPR compliant
Article 30 record, signed DPA, published sub-processor register, documented rights process, rehearsed breach procedure.
EU data residency
Application database and object storage in Ireland. Data at rest does not leave the EEA.
Certified infrastructure
Every sub-processor holds ISO/IEC 27001, SOC 2 Type II, or both.
ISO/IEC 42001 model layer
Both our AI providers hold the international AI management systems standard.
Per-customer isolation
Every bespoke build runs on its own infrastructure, never co-tenanted in a shared database.
Working toward certification
Built to align with ISO/IEC 27001, with certification for Nomad itself on our roadmap.
What is certified, and by whom.
Certified, every one
Every sub-processor that may touch client data holds ISO/IEC 27001, SOC 2 Type II, or both — the hosting, the database, the identity layer, the email, the payments, the model providers. Certifications are listed per vendor below.
ISO/IEC 42001 throughout
Anthropic and OpenAI both hold ISO/IEC 42001:2023, the international standard for AI management systems and the only certifiable AI-governance standard that exists. Every model call we make runs through a provider that holds it.
Built to the standard
Access control, cryptography, operations security, supplier management, incident response and continuity all follow the ISO/IEC 27001 control families, documented in our information security policy and operated day to day.
And the part we won’t blur.
Nomad itself is not yet certified to ISO/IEC 27001 or SOC 2. We are working toward both. Our controls are built to align with ISO/IEC 27001 and are documented in our information security policy, but alignment is not certification and we will not write it as though it were.
When those certifications are granted they will be named on this page with the issuing body and the date. Until then, the honest summary is: certified infrastructure, an ISO/IEC 42001 model layer, GDPR compliance we can evidence, and a company working toward its own certification.
GDPR, with the paperwork to match.
Nomad AI Ltd is registered in Ireland. Our lead supervisory authority is the Irish Data Protection Commission.
Article 30 record
Maintained across both roles — controller for our own processing, processor for client work — with the lawful basis, retention period and transfer basis recorded per activity.
Data processing agreement
A standard Article 28 DPA covering documented instructions, confidentiality, sub-processors, security, breach notification, assistance with data subject rights, international transfers, audit, and deletion or return on termination. We are equally happy to sign yours.
Sub-processor register
Published, and annexed to the DPA with purpose, data categories, country, transfer basis and provider certifications for every vendor. Thirty days' notice before any addition or replacement, with a right to object on reasonable data protection grounds.
Data subject rights
Requests to privacy@nomad.sc, answered within 30 days and usually much faster. Where we process on your instruction as a processor, we route the request to you rather than answering it ourselves, and assist you in responding.
International transfers
Standard Contractual Clauses or the EU–US Data Privacy Framework, recorded per vendor in the sub-processor register.
Breach notification
24 hours to you from the point we become aware, per our DPA, and we will agree a tighter window if you need one. Where a personal data breach is notifiable, 72 hours to the Data Protection Commission.
Retention and deletion
Client material is deleted or returned at the end of an engagement, at your election, and deletion is certified in writing on request. Our own records follow the retention periods recorded per activity in the Article 30 record.
We do not sell personal data, share it for advertising, or reuse client material across engagements.
Your data sits in Ireland.
Primary storage
Our application database and object storage run on Supabase, hosted in AWS eu-west-1 (Ireland). Data at rest does not leave the EEA.
Per-customer isolation
Every bespoke build runs on its own isolated infrastructure. Your data is not co-tenanted with another customer's in a shared application database.
Your stack, if you prefer
Where you would rather we build inside your own cloud tenancy and under your own controls, we do that instead. It is a common arrangement and it changes nothing about how we work.
Some sub-processors are US-incorporated even where the data itself stays in the EEA. Those transfers run on Standard Contractual Clauses or the EU–US Data Privacy Framework, recorded per vendor in the register that ships with our DPA.
Built in, not bolted on afterwards.
Row-level security
Access is enforced in the database itself, by organisation and by role, rather than only in application code. A query that should return nothing returns nothing even if the layer above it is wrong.
Audit logging
Every mutation is written to an audit log with the actor, the action, the target record and the before and after values. The log distinguishes a person acting in the UI from an automated agent from a system job.
Account control
Every external service is signed up under a company domain account, never a personal one, with single sign-on wherever the vendor offers it and multi-factor authentication on every account that supports it. Two directors hold admin on every critical service, so no system has a single point of recovery.
Secrets handling
Human credentials live in a self-hosted password manager; machine secrets and API keys live in a dedicated secrets manager. Secrets do not travel in chat, in email, or in files committed to source control.
Least privilege by default
Access to client material is scoped to the people on that engagement. Sensitive categories are deliberately kept out of the main application database entirely rather than access-controlled within it.
Encryption
TLS in transit throughout, and encryption at rest as provided by the underlying platform. Full-disk encryption is required on every device used for Nomad work.
Change management
Everything in source control, reviewed before it reaches production, with separate staging and production environments holding separate databases and separate credentials.
Backups you can trust
Backups are restore-tested on a recurring schedule against a throwaway environment. An untested backup is not a backup, and we would rather find that out on a quiet Tuesday.
The part most vendors can’t answer.
This is what we do for a living, so our own systems are the worked example.
Certified providers
Anthropic and OpenAI both hold ISO/IEC 42001:2023 for AI management systems, alongside ISO/IEC 27001 and SOC 2 Type II. Certification is a selection criterion for us, not a coincidence.
Model-agnostic
We work across Anthropic, OpenAI, Microsoft and Google. Which one we reach for on your engagement is decided by your stack, your data residency requirements and what your team already knows, not by who we have a relationship with.
Your data is not training data
We use commercial API tiers, whose terms exclude customer content from model training. The provider and the tier are named in the DPA before any client data is processed, and consumer subscription tiers are never used for client data.
A human approves anything consequential
Our own AI layer is the example we would point at. It proposes; it never applies. Nothing it produces takes effect until a named employee approves it, and applying it runs under that person's own authenticated session and permissions.
The model gets no tools it doesn't need
Where a feature only needs text back, the request carries no tools at all, so the model can neither read beyond the context it is handed nor write anywhere. Capability is granted deliberately, per feature, rather than assumed.
Untrusted text is fenced as data
Free text written by third parties through public forms is fenced before it reaches a prompt, so a form submission cannot smuggle instructions into a model that is reading it. Prompt injection is treated as an input-validation problem, because that is what it is.
An off switch that works
AI features ship disabled and can be turned off from an admin screen without a deploy. If you want a feature dark for your organisation, that is a setting, not a support ticket.
DPIAs where they are owed
Where an AI feature processes personal data we record a data protection impact assessment covering the data categories, the lawful basis, the balancing test and the controls, and it is reviewed rather than filed and forgotten.
Everyone who could touch it.
Every vendor that may process personal data in delivering client work. Each one holds ISO/IEC 27001, SOC 2 Type II, or both.
| Sub-processor | Purpose | Region | Certifications |
|---|---|---|---|
| Supabase | Application database, authentication, object storage | Data at rest in Ireland (AWS eu-west-1) | ISO 27001SOC 2 Type II |
| Vercel | Application hosting and edge network | United States | ISO 27001SOC 2 Type II |
| Cloudflare | DNS, CDN, network protection | Global | ISO 27001SOC 2 Type II |
| WorkOS | Single sign-on and directory sync for client portals | United States | ISO 27001SOC 2 Type II |
| GitHub | Source control for client project code | United States | ISO 27001SOC 2 Type II |
| Anthropic | Large language model inference | United States | ISO 42001ISO 27001SOC 2 Type II |
| OpenAI | Large language model inference | United States | ISO 42001ISO 27001SOC 2 Type II |
| Google Workspace | Email, calendar, document collaboration | Ireland, with onward US transfer | ISO 27001SOC 2 & 3 |
| Microsoft | Microsoft 365 tenancy, Azure-hosted tooling | Ireland, with onward US transfer | ISO 27001SOC 2 Type II |
| Liveblocks | Real-time collaboration | United States | SOC 2 Type II |
| Resend | Transactional email delivery | United States | SOC 2 Type II |
| Stripe | Card payment processing | Ireland, with onward US transfer | PCI DSS L1ISO 27001SOC 2 Type II |
| Xero | Accounting ledger and invoicing records | UK / New Zealand (EU adequacy) | ISO 27001SOC 2 |
Vendors used purely for Nomad’s own internal administration — payroll, sales prospecting, recruitment — never touch client data and are outside this register. The full version, with data categories and transfer basis per vendor, is annexed to our DPA. Sub-processors for our own website analytics are listed in the privacy policy.
Incident response.
A written process, rehearsed
A documented procedure covering what counts as an incident, who runs the first hour, and who decides. Rehearsed quarterly as a tabletop exercise, with restore drills on the same cadence.
Containment before investigation
The first action is always to cut access — rotate the credential, wipe the device, kill the session — and investigate second. Directors are notified immediately, before anyone has the full picture.
Notification
24 hours to you from the point we become aware, per our DPA, and tighter if you need it. Where a personal data breach is notifiable, 72 hours to the Data Protection Commission, with legal advice taken the same day.
A write-up, every time
Within 48 hours of containment: what happened, what was affected, what we did, and what we are changing. Blameless by design, and shared with any customer whose data was in scope.
Your security team will want more than a web page.
Email privacy@nomad.sc and we will send the full pack, usually the same day:
- Security overview (one page)
- Data processing agreement
- Full sub-processor register
- Article 30 processing record extract
- Information security policy
- AI usage and governance policy
- Incident response summary
- Completed security questionnaire
We will also complete your own security questionnaire rather than sending ours back at you, sign your DPA if you would rather not use ours, and put a founder on a call with your security function directly. That last one is usually a better use of twenty minutes than a document.