One moment.
One moment.
Available security materials include the SOC 2 Type I and Type II reports, penetration-test summary, SIG-CORE questionnaire, and data-flow diagram. The formal DPA and subprocessor schedule are in preparation with counsel.
Available materials are delivered under mutual NDA and version-pinned to the release you are evaluating. We reply within one business day and deliver available materials within three business days after the mutual NDA.
The formal DPA and subprocessor schedule are in preparation with counsel; nonbinding previews are linked below. The vulnerability disclosure policy is published. Other materials route through the security review form.
| # | Artifact | Version / period | Access | Delivered |
|---|---|---|---|---|
| 01 | SOC 2 Type II report trust services criteria · security, availability, confidentiality | FY2026 · annual | MNDA | within 1 biz day |
| 02 | SOC 2 Type I report point-in-time · historical | 2025 | MNDA | within 1 biz day |
| 03 | Third-party pen-test summary full scope + remediation | v2026.q1 | MNDA | within 1 biz day |
| 04 | Pen-test CVSS remediation log rolling · per-release · SLA-bound | rolling | MNDA | within 3 biz days |
| 05 | Data-processing addendum (DPA) planned coverage · counsel review in progress | template | in preparation | preview |
| 06 | SIG-CORE questionnaire completed · shared assessments framework | 2026 · q2 | MNDA | within 3 biz days |
| 07 | Data-flow diagram per-deployment · signed | v2026.4 | MNDA | within 1 biz day |
| 08 | Subprocessor schedule formal schedule in preparation with counsel | 2026 · q2 | in preparation | preview |
| 09 | Vulnerability disclosure policy scope · safe-harbor · contact | public | published | view policy |
The question legal asks on call one is never "are you SOC 2." It is "what is the contractual treatment of our data." These six answers map one-to-one to DPA clauses.
These six facts describe customer-VPC and on-prem deployments, the production standard for regulated data. Every row is operational, observable in the deployment, enforceable in the contract, falsifiable in audit.
ATS / HRIS read-through only; no replication to Nodes-side storage; no vendor-owned copy of PII, résumés, or interview audio. Last reviewed: July 2026.
Customer-configurable retention. Default is 7 years to match decision-trace reproducibility. Hard-delete workflow signed and logged on request.
Model retrains are per-customer, in-VPC, on customer-consented data only. No cross-tenant pooling. No shared foundation updates from your corpus.
Customer-held KMS, AWS KMS, Azure Key Vault, GCP KMS, HashiCorp Vault. Revocation is a contract-bound kill-switch, not a support ticket.
Okta, Azure AD, Ping, Google Workspace. Group-mapped RBAC. SCIM deprovisioning removes admin access within one hour of an HRIS termination event.
Scoring, admin, and retrain events are hashed and streamed to a customer-owned sink, Splunk, Datadog, or equivalent. Signed decision traces reproducible seven years out.
Controls are implemented in the deployment, not bolted on in policy. For the full boundary manifest, model supply chain, and deployment targets, see Architecture.
Read architectureOne held certification, many operating postures. Every row below states Nodes' actual relationship to that framework, not the customer's. Your own program covers the deployment; we provide the controls and artifacts it depends on.
We do not claim FedRAMP, ISO 27001, HITRUST, NERC CIP, ITAR, CMMC, IL4, IL5, or StateRAMP as Nodes-held. We do not list any as "in progress." This matrix is the whole story.
| Framework | Nodes relationship | What that means in practice |
|---|---|---|
| SOC 2 Type II | Certified · annual | Third-party audit report covering security, availability, and confidentiality. Renewed annually. Available under MNDA. |
| SOC 2 Type I | Certified · historical | Initial point-in-time attestation, superseded operationally by Type II. Available under MNDA. |
| Third-party penetration testing | Assessed · per-release + annual | Contracted tests on every major release plus annual scope. CVSS-tiered remediation SLAs, contractually committed. |
| GDPR · CCPA | Operationally aligned | Planned controller and processor coverage is summarized in the nonbinding DPA preview. Formal terms remain subject to counsel review and the executed agreement. |
| HIPAA | Operationally aligned · customer-certifiable | Technical controls match Security Rule. Customer's own program covers the deployment; we do not hold or claim certification. |
| NYDFS Part 500 · NAIC MDL-671 | Operationally aligned · insurance | Controls map to NYDFS / NAIC; carrier's own program covers use. Live in insurance deployments today. |
| ISO 27001 · ISO 27701 | Not held | SOC 2 is the attestation we maintain. ISO available on customer request via a third-party bridge audit, not a Nodes-side certification. |
| ITAR · EAR · CMMC Level 2 | Not in scope | Requires air-gapped deployment and cleared-personnel program. Available on engagement, not certified by Nodes. |
| FedRAMP · StateRAMP · FISMA | Not in scope | No current FedRAMP authorization. Not claimed as "in progress." Federal engagements run under customer ATO, not Nodes-held. |
| NERC CIP v7 · TSA SD | Not in scope | Energy-sector deployments run under the customer's own CIP program. Nodes provides boundary controls; certification sits with the customer. |
| HITRUST · HITECH | Not held | Not maintained as Nodes-side certifications. Technical controls are HITRUST-aligned; customer's HITRUST program covers the deployment. |
A security program without a public incident posture is not a security program. Left: what happens when something triggers. Right: what actually has.
Architecture carries the long-form engineering questions. These five are the ones that come up in the first call with a security reviewer. Short answers, because these are short questions.
Yes, under mutual NDA. We reply within one business day and deliver available materials within three business days after the mutual NDA.
SOC 2 Type I and Type II only. Alignment to other frameworks is operational: your own program covers the deployment. No FedRAMP authorization, and we do not list it as "in progress." ISO is available as a bridge audit on request.
The formal subprocessor schedule is in preparation with counsel. The nonbinding preview explains the planned coverage and the customer-controlled deployment boundary.
Notification timing is defined in the executed data-processing and security terms, with named customer security contacts. Public disclosure follows our vulnerability disclosure policy.
Use the security request form or email support@nodes.inc. We respond within one business day and deliver available materials within three business days after mutual NDA.
We respond within one business day. Available materials are delivered within three business days after mutual NDA.