ISO 27001:2022
Independently certified, with the entire company in scope. Audited at least annually. View our certificate.
New reportReady or not: why in-house legal teams aren’t ready for the AI they’re being soldRead now→
Nomio is ISO 27001:2022 certified, with the entire company in scope. View our certificate, or visit our Trust Centre for audit-level detail.
Independently certified, with the entire company in scope. Audited at least annually. View our certificate.
Fully compliant with the UK GDPR and Data Protection Act 2018.
Granular, entirely custom permissions. Users and groups only ever see the contracts they should.
Sign-in runs through your own identity provider, so you manage authentication and MFA on your own terms. Nomio supports Single Sign-On with all major providers.

Hosted on AWS, with UK data residency by default and US and EU available.
Your data is kept entirely separate from every other customer’s. Nothing you store in Nomio can ever be seen by another organisation.
Nomio does not train or fine-tune AI models. We use pre-trained models from Anthropic (Claude) and Google (Gemini) under professional licences with zero data retention. Nothing is stored, logged, or used for training.
Every AI request is attributed to the user who makes it, so the AI can only read the contracts that user is allowed to see. Permissions are enforced by fixed rules, never left to a model’s judgement.
The optional Ask AI assistant and MCP connector are read-only, off by default, and scoped to each user’s permissions. Nothing is switched on until you ask for it.
Customer data is hosted on AWS, with UK data residency by default and US and EU available. Data is encrypted at rest (AES-256) and in transit (TLS).
No. Nomio does not train or fine-tune AI models on customer data, and our AI providers operate under professional licences with zero data retention, so nothing is stored, logged, or used for training.
Nomio uses Anthropic (Claude) and Google (Gemini), reached through Google Cloud Vertex AI and Amazon Bedrock under professional licences with zero data retention. Contract text is processed transiently; nothing is persisted by the providers. Stored customer data always remains in the UK.
Yes. Nomio supports SSO via Microsoft Entra ID (Azure AD), Okta, Auth0, Google, JumpCloud, OneLogin, ADFS, and any OAuth 2.0 provider. Customers can enforce MFA on their own users, and MFA is enforced across Nomio’s own systems.
Every document and user belongs to a single organisation, and access checks are enforced on every request, so one organisation can never see another’s data.
Access follows least privilege: staff only get the access they need, on named individual accounts, with MFA enforced.
At contract termination, all customer data in the database is deleted. A full export of your data is available on request. Daily backups used for disaster recovery are retained for up to one year, then deleted under the standard retention policy.
Accredited third parties test all customer-facing systems at least once a year. Independent compliance monitoring runs continuously across the company, and our systems are monitored for suspicious activity around the clock.