Security
Information security
How Nuvinno works to protect information – on the website and in deliveries.
Last updated: 3 August 2026
1. Scope
This page describes information-security principles for nuvinno.com and how we generally work with security in customer deliveries. Detailed security requirements for a specific project are agreed in contract and a data processing agreement where relevant.
2. The website nuvinno.com
For the public website we prioritise:
- Encrypted communication (HTTPS) and modern security headers
- A reduced attack surface (including limited XML-RPC, hardened login and uploads)
- Consent-controlled loading of analytics/marketing tools
- Access control for content administration
3. Deliveries and customer data
When we develop, operate or maintain solutions for customers (including AOS where agreed), we follow among other things:
- Need-based access control (“least privilege”)
- Logging and traceability where relevant for operations and incident handling
- A data processing agreement when we process personal data on behalf of the customer
- Secure development and change practices adapted to the delivery
4. Report a vulnerability
If you have found a security weakness on nuvinno.com or in a solution we are responsible for, we want to hear from you.
Send a description to info@nuvinno.com (preferably mark the subject with “Security”). We acknowledge receipt as soon as we can and follow up within a reasonable time based on severity.
Please do not exploit the finding, do not share details publicly before we have had a chance to assess and fix it, and do not access data that does not belong to you.
5. Privacy
Processing of personal data is described in the privacy policy.