{"@context":"https://certreports.com/llms.txt","vendor":{"slug":"nimble-inc","name":"Nimble","domain":"nimble.com","category":null,"one_liner":null,"trust_center_url":null,"security_page_url":null,"url":"https://certreports.com/vendors/nimble-inc/security","last_verified_at":"2026-09-17T00:00:00.000Z","claimed":false,"verified_profile":false},"attestations":[{"framework":"dpf","framework_name":"EU-US Data Privacy Framework","state":"expired","state_label":"Expired","sentence":"Certificate expiry unknown date passed; no renewal found as of 17 Sep 2026.","kind":"listing","status_text":"Inactive","issued_at":"2016-11-14","expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-17","under_review":false,"source":"dpf","url":"https://certreports.com/vendors/nimble-inc/security","evidence":[{"source_type":"registry","source_name":"Data Privacy Framework list","url":"https://www.dataprivacyframework.gov/participant/6478","fetched_at":"2026-09-17 15:49:36.703131+00","content_hash":"78694fd54fa8f69650ea43db5ca3d2696b26f373bf7561fbf5eb21ea134190cf","wayback_url":null,"quote":"Nimble, Inc.: Inactive","confidence":1}]}],"brief":{"summary":"Nimble was listed in the EU-US Data Privacy Framework registry, with its certification originally issued on 14 Nov 2016, as of 17 Sep 2026. As of 17 Sep 2026, however, that EU-US Data Privacy Framework registry listing shows as inactive rather than current. No public evidence was found for a SOC 2 Type II report for Nimble, as of 19 Sep 2026. No public evidence was found for ISO/IEC 27001 certification for Nimble, as of 19 Sep 2026. No public evidence was found for a PCI DSS certificate for Nimble, as of 19 Sep 2026.","bullets":["EU-US Data Privacy Framework - registry listing inactive as of 17 Sep 2026 (originally issued 14 Nov 2016)","SOC 2 Type II and ISO/IEC 27001 - no public evidence found, as of 19 Sep 2026","PCI DSS - no public evidence found, as of 19 Sep 2026"],"model":"claude-sonnet-5 (subscription)","generated_at":"2026-09-19 12:35:43.305411+00"},"legal_docs":[],"subprocessors":[],"disclaimer":"CertReports indexes public evidence. A missing framework means no public evidence was found at the last check, not that the vendor is non-compliant. SOC 2 is a report, not a certification; HIPAA has no certification.","generated_at":"2026-09-20T00:13:50.779Z"}