Security at NMC Apps

New Mining Company LLC · Program version 1.0 · Reviewed annually

Security at NMC Apps starts from a simple premise: the safest data is the data we never store. Our products are designed to hold the minimum required for their function, and everything we do hold is protected by the controls below. Our information security program is documented in published internal policies, owned by the Managing Director, and reviewed at least annually.

Our policy framework

PolicyWhat it covers
Information Security PolicyProgram principles: least data, least privilege, encryption everywhere, secure development, incident readiness
Access Control PolicyLeast-privilege access, key-only SSH, individual accounts, MFA, 24-hour revocation
Data Classification & Encryption PolicyData classes, TLS 1.2+ in transit, encryption at rest, encrypted backups, retention limits
Network Security & Segregation PolicyIsolated production, default-deny firewalls, brute-force protection, private-interface databases
Vulnerability & Threat Management PolicyAutomatic security updates, dependency scanning, severity-based remediation SLAs
Security Baseline PolicyDaily operational hygiene: screen locking, password manager, MFA, full-disk encryption, clear desk
Incident Response PolicyDefined roles, detect→contain→notify→review process, 72-hour notification commitment
Personal Data Protection PolicyData minimization, purpose limitation, deletion on deauthorization, data subject requests

Key commitments

Reporting a vulnerability

If you believe you have found a security issue in any NMC Apps product or this website, please email [email protected]. We acknowledge reports within 2 business days and do not pursue good-faith researchers.