Security & Compliance
This page describes Nebli, Inc.'s ("Nebli", "we", "us") security practices as of the date above. It is provided for information only, forms no part of any agreement, and creates no warranty or representation. Your agreement with Nebli governs the terms that apply to your use of the Services. No system is completely secure. We update this page as our practices change; the date above reflects the most recent revision.
Certifications and attestations
Nebli holds no third-party security certifications (SOC 2, ISO 27001, FedRAMP) at this time. We build and operate the platform aligned with ISO 27001 controls, and we will update this page if that status changes.
Data encryption
Customer data is encrypted at rest (EBS volume encryption, PostgreSQL TDE, and S3 server-side encryption with AWS KMS). We use TLS at the network edge.
Retrievable per-deployment secrets, including deployment API keys, webhook secrets, and recording share URLs, are encrypted with AES-256-GCM, with the key-encryption key held in AWS Secrets Manager, separate from the database. A separate class of credentials, including service-account API keys, camera and stream keys, and viewer PINs, is stored hashed rather than encrypted.
Data residency
Data is stored in US AWS regions, and AI inference runs in US AWS regions, enforced by an organization-level service control policy. We do not offer LATAM or China data residency. Content-delivery caching uses edge locations in the US, Canada, and Europe.
Access control
The platform uses role-based access control with per-organization tenant isolation. Policy-based authorization enforcement is rolling out progressively.
Audit logging
Security-relevant events are written to a durable audit stream with 365-day retention. For flight-control actions, we maintain a tamper-evident, hash-chained record of the commands the system issued and the responses the aircraft reported. The record is append-only and retained for at least five years, with its integrity verifiable after the fact.
Backups and recovery
We take automated, encrypted backups with point-in-time recovery.
Secrets management
Secrets are sourced from AWS Secrets Manager through External Secrets with IRSA-scoped access, and are never committed to source control.
Responsible disclosure
If you believe you have found a security vulnerability, please report it to security@neblihq.com. We investigate all reports and appreciate coordinated disclosure.
Security diligence
For security questionnaires or diligence during procurement, contact security@neblihq.com. As noted above, Nebli holds no third-party security certifications at this time and does not offer in-country data residency outside the United States.