Know what you’re trusting.
The policies, responsibilities and security decisions behind our work. Start here to understand how we approach your data, what needs to be agreed for your system and how to reach us.
Published policies describe our approach. Project-specific controls, service levels and evidence are confirmed in your engagement.
01 / Security approach
The right person. The right access. A clear record.
We plan security around the data a system holds and the people who use it. OWASP ASVS and ISO/IEC 27001 principles inform this approach; NMT does not claim certification.
Access with a reason
Least privilege, individual accounts, role-based permissions and multi-factor authentication where supported. Access is removed when a role or engagement ends.
Encryption & secure development
HTTPS protects data in transit. Encryption at rest, key management and secret handling are considered against the chosen infrastructure and the project’s data requirements.
Actions that can be traced
Audit trails and activity records can make sensitive actions attributable. The events recorded, access to logs and retention periods are defined for the system being built.
02 / Privacy & processing
Your data has a purpose. And an owner.
We use information submitted to NMT to respond to enquiries and deliver agreed services. In client systems, processing follows the client’s documented instructions and the agreed scope. Your business data remains yours.
POPIA approach
Purpose-specific collection, limited access, retention planning and support for information requests are design considerations from the start.
GDPR readiness
For systems serving international users, we discuss consent, data rights, processing roles and cross-border transfers as part of planning. Readiness is assessed per engagement.
Retention periods depend on the purpose, legal requirements and your project agreement. Client systems can include archiving, deletion and record-age reporting where scoped.
03 / Backup & response
Plan for recovery before you need it.
Backup & recovery
Backup schedules, storage separation, acceptable data loss and recovery times are agreed per system. Your engagement should identify who operates backups and how restores are verified.
Incident response
Our documented approach covers containment, evidence preservation, remediation, client notification and review. System-specific contacts and escalation arrangements belong in the engagement.
04 / Hosting & providers
Know where your system runs.
Client hosting is selected with the client. Provider, region, account ownership, backup location, cross-border processing and third-party services should be recorded for that specific system.
This website and your project are separate environments
This website is hosted on Render. Our published website policy also identifies Google Analytics (Google LLC) and Microsoft Clarity (Microsoft Corporation) for analytics. These are not a default provider list for every client system.
Request the current hosting and subprocessor schedule for your proposed engagement, including email, storage and any other services that will handle your data.
05 / Evidence & agreements
Ask for the evidence your procurement needs.
A policy is useful context; a procurement review may also need project-specific evidence. Tell us whether your review requires independent penetration testing, restore-test records, cyber-insurance cover or security certification so we can confirm the current position and any work needed.
No certification, independent test result or insurance cover is represented by this page. Any evidence supplied should be checked for its date, scope and applicability to your system.
Data Processing Agreement
Request a DPA for your engagement. Processing instructions, security measures, subprocessors, data return and deletion need to reflect the actual work. An approved generic downloadable agreement is not currently published here.
06 / Responsible disclosure
Found something we should investigate?
Send a confidential report to our existing business contact with “Security report” in the subject. Include the affected URL, what you observed, the steps needed to reproduce it and a safe way to reach you.
sales@nokomohoto.comSecurity contact via the NMT business mailbox.
- Share the minimum evidence necessary; leave personal information, credentials and client records out of your initial email.
- Do not access other people’s data, interrupt services or continue testing beyond what you are authorised to do.
- Coordinate disclosure with us while the report is assessed. This contact route is not permission for unauthorised testing or a bug-bounty offer.
07 / Policy library
The full documents, in one place.
Each policy carries its own revision date and detailed scope.
- Privacy Policy
- Terms of Service
- POPIA Compliance Statement
- GDPR Readiness Statement
- Cookie Policy
- Data Processing Policy
- Data Retention Policy
- Information Security Policy
- Access Control Policy
- Acceptable Use Policy
- Incident Response Policy
- Backup & Recovery Policy
- Subprocessor & Third-Party Services Policy
- Client Data Handling Policy
- Website Disclaimer
- Contact Form Consent Notice
Bring your security questions to the first conversation.
Tell us what data you hold, who needs access and what your review requires. We’ll work through the responsibilities with you.
