Last updated: July 25, 2026. This page describes how NYFTY Labs handles data and security. It is written for procurement and security reviewers, and it is deliberately explicit about what we do and do not hold.
Certification status
NYFTY Labs is not SOC 2 certified and is not ISO 27001 certified. We hold no security certification of our own, and we will not imply otherwise. Our infrastructure subprocessors listed below maintain their own SOC 2 Type II attestations for the platforms they operate; those attestations cover their services and do not extend to NYFTY Labs. If your procurement process requires a vendor-held SOC 2 report, we do not meet that requirement today, and we would rather tell you now than during a review.
What we can offer instead: the practices described on this page, a signed Data Processing Agreement, a named subprocessor list, and completed security questionnaires. Several enterprise clients have accepted this in place of a certification; some will not, and that is a reasonable decision.
Subprocessors
We use established platforms rather than self-hosted infrastructure. Each maintains its own compliance program, published on its own trust site:
- Google Workspace (Google LLC), email, documents, and internal collaboration. Compliance
- Microsoft 365 (Microsoft Corporation), productivity and internal collaboration. Trust Center
- Cloudflare, Inc., DNS, TLS termination, WAF, and CDN for our web properties. Trust Hub
- Mailgun (Sinch), transactional email delivery for lead notifications and confirmations.
- Managed hosting, our application and database hosting provider, operating in US data centers.
Client-specific engagements may involve additional platforms that the client already owns and controls (for example Salesforce, NetSuite, Zoho, GoHighLevel, Google Ads, or Meta). We access those systems under the client's own account and permissions; we do not re-host client CRM data.
What data we process, and why
- Website lead submissions, name, email, phone, company, message, the page the form was submitted from, and campaign attribution. Purpose: responding to the enquiry. Retained until it is no longer needed for that purpose or the individual asks us to delete it.
- Website analytics and behavioural events, page views, referrer, campaign parameters, and click events. IP addresses are stored as a keyed hash, not in plain text.
- Client marketing data, accessed inside the client's own platforms under permissions the client grants and can revoke.
- API keys you enter into our free tools, used for that single request and then discarded. They are not written to our databases or logs. See the note on each tool page.
We do not sell personal data. We do not buy contact lists. See our Privacy Statement for individual rights and requests.
Access control
- Multi-factor authentication is required on our administrative platforms and email.
- Administrative dashboards are behind authenticated sessions with role separation (owner, admin, staff); destructive actions are limited to owner and admin roles and are recorded in an audit log.
- Credentials and API keys are held in server-side secret storage, never in front-end code or in a public repository.
- Access is granted per person and removed when an engagement or role ends.
Application and transport security
- All public traffic is served over HTTPS with HSTS enabled.
- Passwords are salted and derived with PBKDF2-SHA256; sensitive comparisons are timing-safe.
- Two-factor authentication (TOTP) is available on dashboard accounts.
- A nonce-based Content Security Policy, same-origin checks on state-changing requests, and layered rate limiting are applied to our application surfaces.
- Private application data is stored outside the public web root; the application refuses to start if that directory would resolve inside it.
- Lead records are written to durable storage before any notification is attempted, so an email failure cannot silently lose an enquiry.
Incident response
If we become aware of a security incident affecting client or personal data, we will: contain it and preserve evidence; assess what data and which parties are affected; notify affected clients without undue delay and, where we act as a processor, within 72 hours of becoming aware; support any notification the client must make to regulators or individuals; and provide a written summary of cause and corrective action once the facts are established. Report a suspected issue to our contact page and mark it urgent.
Continuity and backups
Application code and private data are backed up before risky changes, and production changes are made with a documented rollback path. Hosting-level backups are retained by our hosting provider. We do not claim a contractual recovery-time objective by default; if you need a specific RTO or RPO, raise it during contracting so we can agree something we can actually meet.
Regulated data
We are not a HIPAA Business Associate by default and do not sign BAAs as a matter of course. For dental, medical, and med-spa clients we work with marketing and advertising data, and we ask that protected health information is not sent to us or placed in the systems we access. If your engagement genuinely requires PHI handling, tell us before we start so we can scope it properly or decline. We do not process cardholder data; payments run through the client's own processor.
AI and subprocessing of content
Some of our services and free tools call third-party AI providers. Where our tools ask you to supply your own API key, your request is executed against your account and the key is discarded after that request. Content you submit is processed by the AI provider you have chosen, under that provider's data policy. We do not use client data to train models, and we do not submit client confidential material to consumer AI tools.
Security questionnaires and diligence
We will complete your security questionnaire, sign a mutual NDA, and sign a Data Processing Agreement. We can provide our subprocessor list, a description of data flows for your engagement, and written answers on access control and retention. What we cannot provide is a certification we do not hold, or evidence of an audit that has not happened.
Contact
Security and privacy enquiries, DPA requests, and questionnaires: use our contact page and mark the message as a security or procurement request.
