The EU-US Data Privacy Framework, explained for vendor reviews
Solomon Amos · 7 Sep 2026 · 10 min read
Regulatory evidence
NimbleWork is a leading B2B SaaS provider of collaborative AI-powered Adaptive Work and Project Management products and
For each regulation, how many of the requirements it places on your vendors NimbleWork’s public evidence reaches. Open one for every item with its date and source.
Answers the vendor publishes to questions buyers ask, quoted with the link to where it says so.
Encryption
Do the secure channels for password transmission provide state-of-the-art encryption for all NimbleWork products?
“All NimbleWork products employ industry-standard cryptographic protocols such as TLS (Transport Layer Security) while transmitting passwords. The implementation adheres to the latest cryptographic best practices, ensuring robust encryption algorithms and key management protocols. The encryption cyphers used are regularly updated to mitigate emerging threats and vulnerabilities, maintaining the security and integri...”
as of 21 Sep 2026Source
Encryption
Does all NimbleWork products encrypt data at rest using state-of-the-art encryption for data backups?
“We apply the same encryption methodology used for data at rest to data backups, involving encrypting backup files with the same high-level encryption standards and maintaining security throughout the data lifecycle, including backup storage.”
as of 21 Sep 2026Source
Encryption
Do all NimbleWork subcontractors commissioned to provide the service (e.g., cloud IaaS or PaaS providers) encrypt data at rest using state-of-the-art encryption?
“Subcontractors must implement the same state-of-the-art encryption standards for data at rest. We ensure a uniform and secure approach to data protection across the entire service infrastructure, including subcontracted components.”
as of 21 Sep 2026Source
Encryption
Does the System encrypt data in transit?
“Yes, all data transmitted by our system is encrypted in transit using industry-standard encryption protocols. We enforce the use of TLS 1.2 and 1.3 for all network communications to protect data from interception, eavesdropping, and man-in-the-middle attacks. Strong cipher suites are configured, and we regularly review and update our encryption standards to maintain compliance with current security best practices...”
as of 21 Sep 2026Source
Encryption
How are encryption keys managed and protected?
“Encryption keys are managed using the cloud provider’s Key Management System (KMS), following industry best practices for security and compliance.”
as of 21 Sep 2026Source
Encryption
Do you manage encryption keys internally or rely on third parties?
“We use the underlying cloud provider’s KMS, ensuring keys are stored, rotated, and protected in compliance with global security standards.”
as of 21 Sep 2026Source
Encryption
Does all NimbleWork products encrypt data at rest using state-of-the-art encryption?
“Yes, all customer data stored in our system is encrypted at rest using industry-standard AES-256 encryption. This encryption is applied at the database and storage levels to protect data from unauthorized access. Encryption keys are managed securely using dedicated key management services with strict access controls and regular rotation policies to maintain the highest level of data security.”
as of 21 Sep 2026Source
Penetration testing
Does the organisation conduct periodic assessments of all NimbleWork products about security flaws and vulnerabilities (e.g. penetration tests based on OWASP TOP 10)?
“All NimbleWork products conduct periodic assessments of the cloud service, including quarterly penetration tests by Internal and annually by External auditors based on OWASP TOP 10, to identify and address security flaws and vulnerabilities. This proactive approach helps maintain a high level of security.”
as of 21 Sep 2026Source
Data retention and deletion
Does the organisation issue a confirmation of the irretrievable deletion of all customer data upon expiration of the service contract?
“All NimbleWork products confirm the irretrievable deletion of all customer data upon the expiration of the service contract. This confirmation provides transparency and assures that the data is removed securely and permanently from the system.”
as of 21 Sep 2026Source
Data retention and deletion
Does all NimbleWork subcontractors commissioned with providing the service (e.g. cloud IaaS or PaaS providers) provide irretrievable deletion of data, either on the customer's demand or upon expiration of the service contract?
“Irretrievable data deletion extends to subcontractors commissioned to provide the service. The same standards bind subcontractors to ensure subcontractors delete customer data securely and irreversibly in a coordinated manner.”
as of 21 Sep 2026Source
Data retention and deletion
Does the organisation provide irretrievable deletion of data, either on the customer's demand or upon expiration of the service contract?
“All NimbleWork products provide a mechanism for irretrievable deletion of customer data, adhering to industry best practices and regulatory requirements. We initiate either upon the customer's request or automatically after the service contract expires.”
as of 21 Sep 2026Source
Solomon Amos · 7 Sep 2026 · 10 min read
CertReports Research · 18 Sep 2026 · 12 min read
This maps third-party obligations to the vendor evidence that may support them. It is not legal advice and never a statement that a vendor or its customers comply; confirm scope and sufficiency with your counsel or auditor. “No public evidence” means nothing public was found at the last check. Citations link to the official text.