Security at Nata

You trust Nata with a picture of your security program. Here’s how we look after it.

No passwords

Nata never asks for, stores or checks a password. You sign in with a passkey, or with a single-use email link that expires after 15 minutes and is stored only as a hash. Sessions time out after 60 minutes idle and 12 hours in total, and an admin can sign everyone out at once.

Your data stays yours

Every organization’s data is kept apart twice: the application filters every query by organization, and the database enforces the same rule with row-level security on every table that holds your data.

Secrets are encrypted

Integration tokens and webhook URLs are encrypted before they are stored, with keys we can rotate. For GitHub, Nata stores no token at all: each sync uses a short-lived token that expires within the hour.

Read-only integrations

Nata asks for read access only. The GitHub App reads repository and organization settings, GitLab uses a read-only API scope, and Okta uses a read-only administrator token. Nata never changes anything in the tools you connect.

A record of every change

Changes to your controls, evidence, policies and people are written to an append-only activity log that you can review at any time.

Web security basics

Every state-changing request is protected against cross-site request forgery, sign-in is rate limited, and the app sends strict security headers, including a Content-Security-Policy and HSTS. This website follows the same rules: it loads nothing from other sites and sets no cookies.

Nata’s own compliance

We don’t have a SOC 2 report of our own yet; when we do, we’ll say so here. If you’re reviewing Nata as a vendor, email sales@natasecurity.com and we’ll answer your questionnaire.

Report a vulnerability

If you think you’ve found a security issue in Nata, emailsecurity@natasecurity.com. Please give us a reasonable time to fix it before telling anyone else. We’ll reply, keep you updated, and credit you if you’d like.