Trust & Security
We don't take access to customer data lightly. We have safeguards in place to ensure it is encrypted and protected — so your team can use Naro with confidence.
Your data is never used to train AI models.
Not ours. Not OpenAI's. Not anyone's. The content and conversations you bring into Naro are used solely to power your team's experience — they are not shared with other customers, used to build general models, or retained beyond your control. Your data is yours.
Certifications & Compliance
SOC 2 Type II
AICPA Certified
GDPR
Compliant
CCPA
Compliant
Data Encrypted
At rest & in transit
Google API
Policy compliant
Access Control & Authentication
- Strict access controls with unique SSH keys for production databases
- Unique account credentials required for all application access
- Mandatory multi-factor authentication (MFA) for remote access
- Encrypted connections enforced across all environments
Data Protection & Privacy
- All customer data encrypted at rest and in transit
- Secure protocols for all information transmitted over public networks
- Stringent data retention and disposal policies
- Secure deletion following best practices and regulatory requirements
Monitoring & Incident Response
- Continuous monitoring via intrusion detection systems
- Log management tools for early breach detection
- Robust incident response policies with regular testing
- Rapid and effective response procedures
Governance, Risk & Compliance
- Comprehensive risk management program
- Regular control self-assessments
- Third-party penetration testing performed
- Adherence to industry security best practices
- Cybersecurity insurance maintained
- Mandatory security awareness training for all employees and contractors
Who can access your data
Internal access to customer data follows a strict least-privilege model. Only authorized personnel with a documented business need can access production data, and all access is logged and audited. We never access your data without a support reason — and we'll tell you when we do.
Your data, your exit
You own your data at all times. If you leave Naro, we provide a full data export and permanently delete your data from our systems within 30 days of offboarding. No lock-in, no lingering copies.
Business continuity & recovery
We maintain a documented business continuity and disaster recovery plan with regular testing. Data is backed up continuously, with point-in-time recovery capabilities. Our infrastructure is designed for redundancy so that disruptions don't become your problem.
Going through a security review?
We welcome vendor security assessments. Send us your questionnaire and we'll complete it promptly. We can also provide our SOC 2 report and additional documentation under NDA upon request.
Google API Services
Naro's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We only request access to data necessary to provide our services and do not use Google user data to serve ads or for any purpose unrelated to the core functionality described at the point of authorization.
Questions about security?
Our team is happy to answer questions about our security practices, certifications, or compliance posture.
Contact us