Trust & Compliance

Security & Privacy

NetaMate treats customer confidentiality and service security as core product requirements. This page describes the principles and operational controls that guide how we build and run our services.

Effective date: October 5, 2026

Customer private data is treated as confidential operational data. We do not sell it, rent it or use it for third-party targeted advertising.

1. Security principles

  • Least privilege: administrative and service access is limited to what is needed for the task.
  • Data minimization: collect and retain only what is reasonably necessary for the service or business purpose.
  • Defense in depth: use multiple technical and operational controls rather than relying on a single safeguard.
  • Traceable change: production changes follow controlled deployment and operational processes.
  • Customer control: customers remain responsible for their users, permissions and the data they choose to place in the service.

2. Infrastructure and network controls

NetaMate production services are designed to expose only the network services required for operation. Application components use segmented service networking where appropriate, and administrative access is restricted.

We use infrastructure providers and security services appropriate to the service. Our Subprocessor List identifies providers that may process Customer Data on NetaMate's behalf.

3. Transport and secrets

Public web services use encrypted HTTPS/TLS transport. Credentials, application secrets and deployment credentials are handled separately from public source code and are restricted to authorized operational use.

4. Access control

Access to customer environments and private Customer Data is limited to authorized personnel and service processes with a legitimate operational need. We use role-based or service-specific controls where supported and review access when responsibilities change.

Customers should use strong unique credentials, enable available multi-factor authentication, keep recovery methods current and promptly remove access for users who no longer need it.

5. Secure operations

  • Security-conscious configuration and system hardening.
  • Patch and dependency maintenance based on operational risk.
  • Health checks, service monitoring and troubleshooting controls.
  • Controlled deployments and rollback procedures for production changes.
  • Logging appropriate to security, reliability and support needs.
  • Separation of secrets from committed application source.

6. Backup and resilience

NetaMate maintains backups for selected production data and persistent service files as part of disaster-recovery planning. Backup scope, retention and recovery objectives can vary by product and customer agreement.

Backups reduce recovery risk but do not replace customer responsibilities such as maintaining authorized access, appropriate exports where required and product-specific continuity planning.

7. Privacy by design

We aim to keep privacy decisions close to product and infrastructure design. This includes limiting unnecessary data collection, separating customer environments where appropriate, restricting administrative access and documenting subprocessors that handle Customer Data.

NetaMate does not sell or rent personal information and does not use private Customer Data for third-party targeted advertising.

8. Security incidents

We maintain an incident-response approach for investigating suspected security events, containing affected systems, preserving relevant information, restoring safe operation and communicating with affected customers when required by law or contract.

Where NetaMate acts as a processor and becomes aware of a personal-data breach affecting Customer Data, we will notify the affected customer without undue delay as required by the applicable Data Processing Agreement and law.

9. Shared responsibility

Security is shared between NetaMate and the customer. Customers are responsible for authorized-user management, lawful configuration, endpoint security within their control, appropriate permissions, secure use of credentials and promptly reporting suspected compromise.

10. Report a security issue

If you believe you have found a vulnerability or security issue involving a NetaMate service, send details to support@netamate.com with the subject line Security Report. Please do not access data that is not yours, disrupt production systems or publicly disclose an unresolved issue while we investigate.

11. Scope of this page

This page describes our general approach and is not a certification, audit report, guarantee of absolute security or substitute for a signed customer security schedule. Specific contractual controls, service levels or compliance requirements must be stated in the applicable written agreement.

Questions about this document?
contact@netamate.com