Security at Hoomans
We design every layer of Nera with security in mind — from data encryption to access controls to infrastructure hardening.
Encryption at Rest
All stored data is encrypted using AES-256 with regularly rotated keys. Backups and snapshots follow the same encryption standard.
Encryption in Transit
All network traffic uses TLS 1.3. API endpoints enforce HTTPS-only connections with modern cipher suites and HSTS headers.
Access Controls
Production access is restricted using role-based access control with least-privilege principles. All access is authenticated, authorized, and audited.
Audit Logging
Every action within Nera — content creation, revision, approval, export — is logged with timestamp, actor, and context for full traceability.
Penetration Testing
We conduct regular third-party penetration testing and vulnerability assessments. Findings are prioritized and remediated within defined SLAs.
SOC 2 Compliance
Our security controls align with SOC 2 Type II criteria. Contact us to request our security documentation and compliance reports.
View our full changelog for security updates and infrastructure improvements.
View Changelog