Security and Compliance | Nynch Skip to content
Use cases Product Pricing Cohort Strategy Day Resources Sign in Talk to the founder
Security and compliance

Nynch encrypts customer data in transit and at rest, and isolates each workspace at the row level.

TLS 1.2 or later in transit. Encryption at rest. Row-level security between customers. Nynch does not train shared models on your network. This page is the current security stance, not a badge wall. Nynch is annual only. Solo is $79 a month, billed once a year at $950. Pro is $199 a month, billed annually. Team is by application. Founder Member is £3,700 paid in full or £1,450 a month for three months. There is no free trial and no 90-day pilot.

Talk to the founder

30 minutes. On your real data. Not generic slides.

The four pillars.

Each pillar lists what is actually in place today. Nothing here is aspirational. Where a control is partial or in progress, it is called out explicitly in the Status Snapshot below.

Pillar 1

Data protection

  • Encryption in transit using TLS 1.2 or later
  • Encryption at rest using industry-standard symmetric encryption
  • Database-level encryption layered on disk-level encryption
  • Encrypted backups with keys held separately from encrypted data
  • Customer data isolated by workspace at the row level
Pillar 2

Access and identity

  • Role-based access controls on every team workspace
  • Workspace-level data isolation between customers
  • Supabase-level row-level security for every table
  • Audit logging on sensitive admin actions
  • Per-action change tracking for record edits
Pillar 3

Privacy and data control

  • UK GDPR and EU GDPR compliant posture
  • European data residency for primary storage
  • Standard Contractual Clauses for any international transfer
  • Customer-initiated export in machine-readable format
  • Account deletion within 30 days of request
Pillar 4

Operational practice

  • SOC 2-aligned controls (certification on roadmap)
  • Documented incident response procedure
  • 72-hour supervisory-authority breach notification
  • Quarterly access review of admin privileges
  • Subprocessor list maintained and reviewable on request

Status snapshot.

The short version. What is in place today, what is in flight, and what is on the roadmap.

Control Status Notes
Encryption in transit (TLS 1.2 plus) In place All API and web traffic
Encryption at rest In place Disk-level plus database-level
Role-based access controls In place Workspace-scoped roles
UK GDPR compliance In place UK-based controller
EU GDPR compliance In place European data residency
Single sign-on (SAML / SSO) In place Available on request for firms
SOC 2 Type II certification On roadmap SOC 2-aligned today. Formal report later.
HIPAA compliance Not in scope Nynch is not a healthcare CRM
Customer data trains shared AI Never (structural) Each Learning Ledger is private
Subprocessor list Reviewable on request Email security@nynch.com

The privacy promise that holds up under questioning.

Structural, not configurable

Your Superbrain trains on you. It does not train on anyone else.

Every Nynch customer's Learning Ledger is a private record of every AI suggestion the system has made for that customer, every action the customer took, and every outcome that followed. Ledgers are never pooled across accounts.

This is structural. It is not a checkbox in a settings panel that can be toggled. The architecture does not support cross-customer training, by design. When a buyer asks "how do I know my client conversations are not being used to train the model for your other customers?" the answer is that there is no model that can be trained that way. Each customer's Superbrain is calibrated to that customer alone.

Where to send the procurement questionnaire.

If you are a buyer's procurement or security team and you need anything not covered above, the right channel depends on what you need.

Security questions

Procurement questionnaires, subprocessor list requests, security control deep-dives.

security@nynch.com

Privacy / data subject requests

UK and EU GDPR data subject access requests, deletion requests, processing inquiries.

privacy@nynch.com

Incident reporting

Suspected vulnerability or active incident. We respond within one business day.

security@nynch.com

For full data-handling detail see the Privacy Policy. For terms of service see Terms. For cookie usage see Cookies.

Need a procurement-grade walkthrough?

Book a 30-minute call. We will walk through the security questionnaire your team has, share the subprocessor list, and answer everything in the open. No NDA required for any of the controls listed above.

Talk to the founder

30 minutes. On your real data. Not generic slides.