New reportReady or not: why in-house legal teams aren’t ready for the AI they’re being soldRead now

Security

Enterprise-grade security means we never compromise on your contracts’ safety

Nomio is ISO 27001:2022 certified, with the entire company in scope. View our certificate, or visit our Trust Centre for audit-level detail.

ISO 27001 certified

Certifications and audits

ISO 27001:2022

Independently certified, with the entire company in scope. Audited at least annually. View our certificate.

GDPR

Fully compliant with the UK GDPR and Data Protection Act 2018.

How we protect your data

You decide who sees what

Granular, entirely custom permissions. Users and groups only ever see the contracts they should.

You control access

Sign-in runs through your own identity provider, so you manage authentication and MFA on your own terms. Nomio supports Single Sign-On with all major providers.

  • Microsoft Entra ID
  • Okta
  • Google
  • Auth0
  • OneLogin
  • JumpCloud

UK data residency

Hosted on AWS, with UK data residency by default and US and EU available.

Isolated per organisation

Your data is kept entirely separate from every other customer’s. Nothing you store in Nomio can ever be seen by another organisation.

How we use AI

We don’t train on your data

Nomio does not train or fine-tune AI models. We use pre-trained models from Anthropic (Claude) and Google (Gemini) under professional licences with zero data retention. Nothing is stored, logged, or used for training.

The AI only sees what you can see

Every AI request is attributed to the user who makes it, so the AI can only read the contracts that user is allowed to see. Permissions are enforced by fixed rules, never left to a model’s judgement.

Read-only, and off by default

The optional Ask AI assistant and MCP connector are read-only, off by default, and scoped to each user’s permissions. Nothing is switched on until you ask for it.

Frequently asked questions

Customer data is hosted on AWS, with UK data residency by default and US and EU available. Data is encrypted at rest (AES-256) and in transit (TLS).

No. Nomio does not train or fine-tune AI models on customer data, and our AI providers operate under professional licences with zero data retention, so nothing is stored, logged, or used for training.

Nomio uses Anthropic (Claude) and Google (Gemini), reached through Google Cloud Vertex AI and Amazon Bedrock under professional licences with zero data retention. Contract text is processed transiently; nothing is persisted by the providers. Stored customer data always remains in the UK.

Yes. Nomio supports SSO via Microsoft Entra ID (Azure AD), Okta, Auth0, Google, JumpCloud, OneLogin, ADFS, and any OAuth 2.0 provider. Customers can enforce MFA on their own users, and MFA is enforced across Nomio’s own systems.

Every document and user belongs to a single organisation, and access checks are enforced on every request, so one organisation can never see another’s data.

Access follows least privilege: staff only get the access they need, on named individual accounts, with MFA enforced.

At contract termination, all customer data in the database is deleted. A full export of your data is available on request. Daily backups used for disaster recovery are retained for up to one year, then deleted under the standard retention policy.

Accredited third parties test all customer-facing systems at least once a year. Independent compliance monitoring runs continuously across the company, and our systems are monitored for suspicious activity around the clock.

Your contracts shouldn’t live in someone’s head