Hoomans
Security

Security at Hoomans

We design every layer of Nera with security in mind — from data encryption to access controls to infrastructure hardening.

Encryption at Rest

All stored data is encrypted using AES-256 with regularly rotated keys. Backups and snapshots follow the same encryption standard.

Encryption in Transit

All network traffic uses TLS 1.3. API endpoints enforce HTTPS-only connections with modern cipher suites and HSTS headers.

Access Controls

Production access is restricted using role-based access control with least-privilege principles. All access is authenticated, authorized, and audited.

Audit Logging

Every action within Nera — content creation, revision, approval, export — is logged with timestamp, actor, and context for full traceability.

Penetration Testing

We conduct regular third-party penetration testing and vulnerability assessments. Findings are prioritized and remediated within defined SLAs.

SOC 2 Compliance

Our security controls align with SOC 2 Type II criteria. Contact us to request our security documentation and compliance reports.

View our full changelog for security updates and infrastructure improvements.

View Changelog