Last updated 24 August 2026
Security Notice
How security works in our delivery model, what we ship into your environment, how our people work inside it, and how we run our own systems.
1. How security works in our delivery model
Our products run in your environment. Agents run on the enterprise AI platform you contract: Claude Cowork, Copilot Cowork, ChatGPT Work, Vibe Work, or your in-house agentic AI. TP Warehouse runs as a dedicated deployment in your cloud. In product operation your data does not pass through Supernomial systems.
On this page, your environment means the enterprise AI platform you contract, the cloud accounts you control, and your systems, tenants, repositories and communication channels.
Our security program has three parts: the integrity of what we ship into your environment; how our people work inside your environment during an engagement; and the security of our own company systems (website, contact data, source code, devices and accounts).
Our controls are designed to meet the standards our clients are certified against: ISO 27001 internationally, SOC 2 in the United States. We have no certification and publish no audit report. For your review we answer your questionnaire, walk your security and data protection teams through each data path, and provide our policies under NDA.
This page is a notice and states our controls; the data-path pictures and the short answers to standard vendor questions are on Data & Security. Where a sentence here also appears in the Terms of Service or the Data Processing Agreement, it is binding there; section 12 of this notice says how to obtain a copy for attachment to an Order.
2. Ownership and program
Security is owned by the founders; hello@supernomial.co reaches them directly. We keep written policies proportionate to our size (information security, access control, incident response, secure development and vendor management), an asset inventory and a risk register, and we review them at least once a year. Everyone with access to company systems is bound by confidentiality terms, and access is removed when they leave.
3. What we ship, per offering
3.1 Managed Agents on your AI platform
What we ship is text your team can read: instruction files, knowledge, templates and workflows, kept in our code repository and delivered through the marketplace of your platform; the components of each release are listed in its release notes. Prompts, files and outputs stay on your platform under your platform agreement, which covers model traffic, storage, retention and training. As delivered, the products contain no Supernomial endpoint, account, API key, license check or telemetry and transmit none of your content to Supernomial. Updates arrive through the marketplace channel you configure. Where your platform fetches updates from a Supernomial-published marketplace or repository, or a skill reads public reference files (country profiles, industry benchmarks) from a repository we publish at the moment they are used, each fetch or read is one-directional, goes to the hosting provider and not to us, is logged there under its own terms (requesting address, client software, time, requested file and any account the host requires), and carries none of your content. The reference files are read from their current published version, outside the pinned release, and are versioned in the same public repository, so your team can review their history. Where your platform supports it, your administrators pin the reviewed revision and its digest. Where a deliverable is rendered to PDF and no LaTeX installation is found, the rendering script installs an open-source TeX distribution from its public mirror on first use; your administrators can pre-install it instead. Other reference content is fetched read-only from public sources; web research runs only when a user asks for it.
3.2 Private Agents
The same components, deployed in infrastructure you control outright: your own code repository and marketplace (including the reference files, where you mirror them), your region, your identity provider, your network, your logging and retention. We configure them with you; you keep the keys and the administrator roles.
3.3 TP Warehouse
One deployment per customer: a managed database and sign-in platform in your own account plus the cloud platform we bring it up on with you, in the region you choose; no shared tenancy; both contracted by you. Agents reach it over MCP (the Model Context Protocol) from inside your environment, and model calls go to the model vendor you configure. The baseline we implement with your team: TLS in transit; encryption at rest by the platforms you contract; sign-in through the deployment's identity service, with single sign-on through your identity provider where you configure it; least-privilege access for agents and people, enforced at the database; private networking where your policy asks for it and the platform supports it; an audit trail of who changed what and when; backups under your platforms' settings. TP Warehouse is delivered with an open-source notice file and a component list.
3.4 Engagement work
During an engagement our people work inside your environment with identities you issue, for the time you set, under your terms. We keep no standing access and no credentials, and no copies of your data outside your environment beyond engagement correspondence and the working notes and deliverable drafts an engagement needs, which we delete within 30 days of its end under the Data Processing Agreement. The Data Processing Agreement applies whenever our people access your environment or receive your personal data in the course of engagement work.
4. Supply-chain integrity of what we ship
Every release is versioned, carries release notes, and can be reviewed by your administrators before installation. Source is kept in access-controlled repositories; changes are reviewed before release; secrets never live in code. We use AI tools in our own engineering. A person reviews every change before it ships. Changes to knowledge and playbooks pass a transfer pricing review by a transfer pricing professional on our team, AI-assisted, and a person signs them off before release; automated checks run in our build process. Updates do not alter the permissions, connectors or approval gates configured in your environment, and any update that adds a connector or an action needing new permissions is described in the release notes and disabled until your administrator enables it.
5. Encryption and key management
Our systems: TLS for every connection; data at rest encrypted by each provider that stores it (Vercel, Supabase, Resend, Google Workspace for our mail, GitHub for source); no customer product data stored. Your environments: encryption is your platform's and your cloud's; for TP Warehouse, at rest by the platforms you contract (section 3.3).
6. Access control
Company systems: named accounts; multi-factor authentication on every service we administer (source hosting, web hosting, database, email and identity); least privilege; periodic access review; same-day removal on departure; full-disk encryption and a password manager on company devices.
Customer environments: access only through identities you issue; time-bound; logged on your side; no shared accounts; no credentials stored by us. Your security and acceptable-use policies bind our people while they are inside, and subcontractors enter only with your consent.
7. Secure development
Code is reviewed before it is merged, dependencies are kept updated, and no customer product data is used in development, because none reaches us; website form records are not copied into development or test environments. Content is treated as code: versioned, reviewed and tested on sample cases before release.
Our agent design practice (a practice, since a model may not follow every instruction): retrieved and uploaded content is handled as data and carries no authority to instruct an agent; sensitive actions wait behind the approval policies you configure on your platform; guardrails name what agents never do without your sign-off.
8. Vendor management
Our vendor list is short and public: see Sub-processors and vendors on the Trust Center overview and the Privacy Policy. New vendors are assessed before use (purpose, data touched, region, security documentation) and reviewed annually. No vendor touches customer product data, because there is none on our side.
9. Incident response and notification
hello@supernomial.co is the channel, and the founders monitor it. We log, triage, contain and fix.
If a security incident affects personal data we process on your behalf or a deliverable we shipped to you, we notify your named contact (for evaluation installs, the administrator who installed the plugin, where we know them) without undue delay, and in any event within 48 hours after becoming aware. "Aware" means a reasonable degree of certainty that an incident has occurred. The first notice may be partial and is completed as facts develop; a written post-incident summary follows; we make no public statement naming you without your consent, unless the law requires it. Where we act as your processor, notice is timed so you can meet your own deadline under Article 33 GDPR. If a defect in shipped content could cause harmful agent behavior, we issue an advisory and a patched release.
10. Business continuity
Your agents and your warehouse keep running if our systems are down: they run on your platform and your cloud, and every engagement ends with documentation written so the system works without us. Our own systems: source code in access-controlled repositories; the website on a managed host; contact and newsletter data in a managed database that contains nothing any customer system depends on. We are a small team; key-person risk is addressed with documentation and with you keeping everything needed to run.
11. Vulnerability disclosure
Report security issues to hello@supernomial.co. The same contact is published in machine-readable form at /.well-known/security.txt.
11.1 Scope
supernomial.co, welcome.supernomial.co, and the software we ship to customers, tested in an environment you control. Out of scope: environments that are not yours, the AI platforms and cloud providers our customers use (report to them), social engineering, denial of service, and physical testing.
11.2 Rules
Stop at proof of concept. Test only with accounts you own. Do not access, modify or delete data that is not yours. No privacy violations and no service degradation. Give us a reasonable time to fix before you disclose. Do not make payment a condition of reporting.
11.3 Safe harbor
Good-faith research within these rules is authorized, and we will not pursue claims or complaints for it; the Terms of Service (section 22.1) permit it. We cannot authorize testing of third-party systems, and testing must also respect the testing policies of our hosting providers (Vercel, Supabase and Resend).
11.4 What we promise
Acknowledgment within 3 business days, triage within 10 business days, status updates until the issue is fixed, and credit on request. We run no bounty program. For defects in software we ship we issue advisories and patched releases, critical issues first. Traficom's NCSC-FI (vulncoord@traficom.fi) can coordinate cases that involve several parties.
12. Customer security reviews
Send your questionnaire (SIG, CAIQ or your own) to hello@supernomial.co; first response within 5 business days. We answer it and sit with your security and data protection teams until every question is closed.
What we provide: an architecture walkthrough per offering; this Security Notice and Data & Security; the plugin release for your review before installation; our policies under NDA; and, for attachment to an Order, a copy of the security commitments in the Terms of Service and the Data Processing Agreement (Annex II), available on request at hello@supernomial.co.
What we cannot provide today: a SOC 2 report, an ISO 27001 certificate, or a third-party penetration test report of our own systems (not yet commissioned). You may test your TP Warehouse deployment in your own cloud under your rules.
13. Certifications and regulation
Our controls are designed to meet the standards our clients are certified against: ISO 27001 internationally, SOC 2 in the United States. We have no certification and publish no audit report. For your review we answer your questionnaire, walk your security and data protection teams through each data path, and provide our policies under NDA.
EU AI Act: Our agents are built for transfer pricing work by qualified professionals and are not intended for any use the EU AI Act lists as high-risk. The obligations for the underlying models sit with your AI platform. The transparency duties that apply since 2 August 2026 are met by design: agents are identified as agents, and their work passes your review before it leaves your organization. Our EU AI Act classification note is available on request. We will tell you if the intended purpose changes.
GDPR: in product operation we do not process your personal data; whenever our people access your environment or receive your personal data in engagement work, the Data Processing Agreement applies; for the website the Privacy Policy applies.
Your platform's and your cloud's certifications: check them at the source, Anthropic Trust Center, Microsoft Trust Center, OpenAI Trust Portal, Mistral AI Trust Center.
14. What we do not do
- We do not train models, on your data or anyone's.
- We do not route your data through our systems: no product telemetry, no license server, no hidden calls home. In product operation nothing calls a Supernomial system; the only related traffic is the update fetch, the reference-file reads and the one-time TeX installation described in section 3.1, which go to their public hosts, are logged there, and carry none of your content.
- We do not keep standing access to your environment or copies of your data, beyond engagement correspondence and the working notes and deliverable drafts an engagement needs, which we delete within 30 days of its end (section 3.4).
- We do not sell contact data and pass it on only to the recipients named in the Privacy Policy (section 3). We do not use cookies or any technology that stores or reads information on your device; site usage is measured without cookies through our host’s analytics (aggregated page metrics, nothing stored on your device). When you sign in to the customer portal, your browser keeps a session marker for that tab only; it is deleted when the tab closes. The sign-in buttons load code from Google and Microsoft when you click them; their notices apply to that step.
- We do not claim certifications, audits, insurance or tests we do not have.
15. Contacts
Supernomial Oy, Business ID 3542056-6, Bulevardi 21, 00180 Helsinki, Finland. Security reports, questionnaires, privacy and data protection, general and legal notices: hello@supernomial.co.