Trust & security
How we protect
your data.
We limit data collection, restrict access and encrypt data in transit and at rest. This page describes our controls and current audit status.
Compliance and audits
GDPR
European Union
Swiss FADP
Switzerland
SOC 2 Type I
Audited
Google CASA
Tier 2, in review
How we protect your data
Protection at each step.
Encryption at rest
All persisted data is encrypted with AES-256 using managed keys rotated on a regular schedule.
Encryption in transit
Every connection uses TLS 1.3 with strong cipher suites. We disable legacy protocols and weak ciphers across our infrastructure.
Least-privilege access
Production systems are gated behind SSO, hardware-key MFA, and just-in-time access controls. No standing admin credentials.
Audit logs
Critical actions on user data are logged, immutable, and retained for review. Logs are stored separately from the systems they observe.
Secure development lifecycle
Static analysis, dependency scanning, and code review on every change. Production deploys flow through automated checks.
Vulnerability management
Continuous monitoring, regular third-party penetration testing, and a clear remediation SLA based on severity.
Responsible disclosure
Found a vulnerability? Tell us first, in private.
We welcome reports from independent researchers. Send details, reproduction steps, and any proof-of-concept to ops@natura.inc. We acknowledge within 72 hours and keep you updated through remediation.
Machine-readable disclosure policy (RFC 9116): /.well-known/security.txt.
Subprocessors
Who handles your data with us.
Updated: May 30, 2026
We rely on a small set of vetted subprocessors to operate the Services. Each is bound by a Data Processing Agreement and applicable safeguards for international transfers.
Questions about security?
For audit reports, DPAs, or anything else, write to our security team. We respond within two business days.
ops@natura.inc