Loading Natura
Skip to content

Trust & security

How we protect
your data.

We limit data collection, restrict access and encrypt data in transit and at rest. This page describes our controls and current audit status.

Compliance and audits

GDPR

European Union

Compliant

Swiss FADP

Switzerland

Compliant

SOC 2 Type I

Audited

Compliant

Google CASA

Tier 2, in review

In progress

How we protect your data

Protection at each step.

  • Encryption at rest

    All persisted data is encrypted with AES-256 using managed keys rotated on a regular schedule.

  • Encryption in transit

    Every connection uses TLS 1.3 with strong cipher suites. We disable legacy protocols and weak ciphers across our infrastructure.

  • Least-privilege access

    Production systems are gated behind SSO, hardware-key MFA, and just-in-time access controls. No standing admin credentials.

  • Audit logs

    Critical actions on user data are logged, immutable, and retained for review. Logs are stored separately from the systems they observe.

  • Secure development lifecycle

    Static analysis, dependency scanning, and code review on every change. Production deploys flow through automated checks.

  • Vulnerability management

    Continuous monitoring, regular third-party penetration testing, and a clear remediation SLA based on severity.

Responsible disclosure

Found a vulnerability? Tell us first, in private.

We welcome reports from independent researchers. Send details, reproduction steps, and any proof-of-concept to ops@natura.inc. We acknowledge within 72 hours and keep you updated through remediation.

Report a vulnerabilityPGP key: published on request

Machine-readable disclosure policy (RFC 9116): /.well-known/security.txt.

Subprocessors

Who handles your data with us.

Updated: May 30, 2026

We rely on a small set of vetted subprocessors to operate the Services. Each is bound by a Data Processing Agreement and applicable safeguards for international transfers.

Vercel
Web hosting and edge delivery
EU / US
Supabase
Primary database
EU (Frankfurt)
AI model providers
LLM inference for Agent responses (DPA in place)
US
Google Cloud
Gmail / Calendar OAuth APIs
US / EU
Resend
Transactional email
US / EU
Cloudflare
Backend infrastructure and media storage (voice notes)
US / EU
ElevenLabs
Real-time voice (speech-to-text, text-to-speech), zero-retention
US
Composio
Authentication
US
Expo
Push notification delivery
US
Twilio
Voice / telephony for calls
US

Questions about security?

For audit reports, DPAs, or anything else, write to our security team. We respond within two business days.

ops@natura.inc