The details your reviewer will ask for
- How things are encrypted
- Documents are encrypted on your own device, before upload, using standard, widely audited cryptography. Everything in transit is encrypted. We don’t invent our own algorithms, and we don’t publish a spec sheet here. The full technical detail is in our security documentation, available on request to security@nakodax.com.
- Where things are held
- Permissions, access rules, and access history are held in [region/provider: e.g. AWS Mumbai and Frankfurt]. The contents of your documents, data and code are not held by us at all. [Confirm regions and whether customers can choose residency.]
- Availability
- Opening a protected file requires reaching us. That is the mechanism, not a weakness: a file that opens without checking is a file you’ve permanently given away. It also means uptime is a contractual commitment on our side, not a marketing line. [State the SLA once defined.] Brief network interruptions are tolerated by design, so a short outage does not take a customer’s production system down.
- Certifications
- [State honestly: e.g. “SOC 2 Type I in progress, expected Q4 2026. Our security questionnaire answers are available today.” If nothing is in progress, say what the roadmap is.]
- Subprocessors
- [List them: cloud provider, email, analytics, payments. Reviewers always ask, and publishing it saves a week of back and forth.]
- Reporting a vulnerability
- Found something? Tell us at security@nakodax.com. We respond, we fix, and we credit researchers who report responsibly.