Security at NMC Apps
Security at NMC Apps starts from a simple premise: the safest data is the data we never store. Our products are designed to hold the minimum required for their function, and everything we do hold is protected by the controls below. Our information security program is documented in published internal policies, owned by the Managing Director, and reviewed at least annually.
Our policy framework
| Policy | What it covers |
|---|---|
| Information Security Policy | Program principles: least data, least privilege, encryption everywhere, secure development, incident readiness |
| Access Control Policy | Least-privilege access, key-only SSH, individual accounts, MFA, 24-hour revocation |
| Data Classification & Encryption Policy | Data classes, TLS 1.2+ in transit, encryption at rest, encrypted backups, retention limits |
| Network Security & Segregation Policy | Isolated production, default-deny firewalls, brute-force protection, private-interface databases |
| Vulnerability & Threat Management Policy | Automatic security updates, dependency scanning, severity-based remediation SLAs |
| Security Baseline Policy | Daily operational hygiene: screen locking, password manager, MFA, full-disk encryption, clear desk |
| Incident Response Policy | Defined roles, detect→contain→notify→review process, 72-hour notification commitment |
| Personal Data Protection Policy | Data minimization, purpose limitation, deletion on deauthorization, data subject requests |
Key commitments
- Data minimization: we do not persist buyer personal details — only order identifiers and settlement records needed for reconciliation.
- Encryption: TLS 1.2+ for every connection; encryption at rest for production data, backups, and workstations.
- Access: least privilege, key-based authentication only, MFA on all supporting services.
- Deletion: shop data deleted within 30 days of deauthorization or verified request.
- Incident notification: affected sellers and platforms notified within 72 hours of a confirmed incident.
Reporting a vulnerability
If you believe you have found a security issue in any NMC Apps product or this website, please email [email protected]. We acknowledge reports within 2 business days and do not pursue good-faith researchers.
NMC Apps