Last updated: July 25, 2026. This page describes how NYFTY Labs handles data and security. It is written for procurement and security reviewers, and it is deliberately explicit about what we do and do not hold.
Certification status
NYFTY Labs is not SOC 2 certified and is not ISO 27001 certified. We hold no security certification of our own, and we will not imply otherwise. The infrastructure providers listed below each maintain their own compliance programs for the platforms they operate; see their trust pages for the current scope and report type. Whatever they hold covers their services and does not extend to NYFTY Labs. If your procurement process requires a vendor-held SOC 2 report, we do not meet that requirement today, and we would rather tell you now than during a review.
What we can offer instead: the practices described on this page, a signed Data Processing Agreement, a named subprocessor list, and completed security questionnaires. Several enterprise clients have accepted this in place of a certification; some will not, and that is a reasonable decision.
Subprocessors
We use established platforms rather than self-hosted infrastructure. Each maintains its own compliance program, published on its own trust site:
- Google Workspace (Google LLC); email, documents, and internal collaboration. Compliance
- Microsoft 365 (Microsoft Corporation); productivity and internal collaboration. Trust Center
- Cloudflare, Inc.; DNS, TLS termination, and CDN for our web properties. Trust Hub
- Mailgun (Sinch), transactional email delivery for lead notifications and confirmations.
- Managed hosting, our application and database hosting provider, operating in US data centers. Named on request under NDA.
- AI providers; OpenRouter (which acts as a routing intermediary to upstream model providers such as OpenAI, Anthropic and Google), and direct use of Anthropic and OpenAI. Used for content drafting, AI-visibility measurement, and operational diagnostics. Prompts and the content we submit are processed by the selected provider under that provider's own data policy.
Client-specific engagements may involve additional platforms that the client already owns and controls (for example Salesforce, NetSuite, Zoho, GoHighLevel, Google Ads, or Meta). We access those systems under the client's own account and permissions; we do not re-host client CRM data.
What data we process, and why
- Website lead submissions; name, email, phone, company, message, the page the form was submitted from, and campaign attribution. Purpose: responding to the enquiry. Retained until it is no longer needed for that purpose or the individual asks us to delete it.
- Website analytics and behavioural events; page views, referrer, campaign parameters, and click events. In our analytics store, IP addresses are reduced to a salted hash and never retained in plain text. Our CDN and hosting provider keep their own access logs under their retention policies.
- Client marketing data, accessed inside the client's own platforms under permissions the client grants and can revoke.
- API keys you enter into our free tools, held in memory for the duration of that request and then discarded. We do not intentionally store or log them, and our tool backends run secret-scrubbing on log output. See the note on each tool page.
We do not sell personal data. We do not buy contact lists. See our Privacy Statement for individual rights and requests.
Access control
- Administrative accounts are individually named, there are no shared or generic logins, and two-factor authentication (TOTP) is available and can be enforced per account.
- Administrative dashboards are behind authenticated sessions with role separation (owner, admin, staff); destructive actions are limited to owner and admin roles and are recorded in an audit trail on the admin surfaces that expose them.
- Credentials and API keys are held in server-side secret storage, never in front-end code or in a public repository.
- Access is granted per person and removed when an engagement or role ends.
Application and transport security
- All public traffic is served over HTTPS with HSTS enabled.
- Passwords are salted and derived with PBKDF2-SHA256; sensitive comparisons are timing-safe.
- A nonce-based Content Security Policy, same-origin checks on state-changing requests, and layered rate limiting are applied to our application surfaces.
- Private application data is stored outside the public web root; the application refuses to start if that directory would resolve inside it.
- Lead records are written to durable storage before any notification is attempted, so an email failure cannot silently lose an enquiry.
Monitoring and incident response
Application errors and security-relevant events are written to private server-side logs, administrative and destructive actions are recorded in an audit trail, and a watchdog process performs health checks and alerts on failure. We do not operate a 24/7 staffed security operations centre, and we will not claim one.
If we become aware of a security incident affecting client or personal data, we will: contain it and preserve evidence; assess what data and which parties are affected; notify affected clients without undue delay, and within the timeframe set out in the Data Processing Agreement for that engagement; support any notification the client must make to regulators or individuals; and provide a written summary of cause and corrective action once the facts are established. Report a suspected issue to our contact page and mark it urgent.
Continuity and backups
Application code and private data are backed up before risky changes, and production changes are made with a documented rollback path. Hosting-level backups are retained by our hosting provider. We do not claim a contractual recovery-time objective by default; if you need a specific RTO or RPO, raise it during contracting so we can agree something we can actually meet.
Regulated data
Protected health information is out of scope for our engagements. For dental, medical, and med-spa clients we work with marketing and advertising data. Where an engagement would require access to a system that contains PHI, we execute a Business Associate Agreement before that access begins, or we decline that part of the scope.
In client marketing engagements we do not process or store cardholder data; payments run through the client’s own processor. Our own billing runs through a third-party payment processor and we do not store card numbers.
AI and subprocessing of content
Two distinct paths, and the difference matters for your review:
- Bring-your-own-key tools. Where a tool asks you to supply your own API key, the request runs against your provider account and the key is discarded after that request.
- Services that run on our keys. Content drafting, AI-visibility measurement, and operational diagnostics use API keys we hold (see the AI providers entry in the subprocessor list). Content submitted on those paths is processed by that provider under its own data policy.
We do not use client data to train models, and we do not submit client confidential material to consumer AI tools.
Security questionnaires and diligence
We will complete your security questionnaire, sign a mutual NDA, and sign a Data Processing Agreement. We can provide our subprocessor list, a description of data flows for your engagement, and written answers on access control and retention. What we cannot provide is a certification we do not hold, or evidence of an audit that has not happened.
Contact
Security and privacy enquiries, DPA requests, and questionnaires: use our contact page and mark the message as a security or procurement request.
