Trust & security

Quiet, careful, and yours.

You're trusting NestPoint with your members' information. We don't take that lightly. Here's how we approach that responsibility, in plain language.

Your data, isolated

Each organization works within its own workspace, with records scoped to that workspace throughout the application.

Backups every day

Backups support recovery when something goes wrong. Ask us for the current schedule and restoration process.

Activity history

Supported actions record who made a change, when it happened, and which record was affected.

Real support

Talk with someone who knows the product and can understand the workflow behind your question.

How we handle your data

Safeguards you can review and understand.

NestPoint uses workspace scoping, encryption, backups, access controls, and activity records to protect member information. The exact coverage and operating details matter, so we are happy to review current documentation with your team.

  • Workspace-scoped records and access checks throughout the application.
  • Encryption in transit over HTTPS and at rest at the infrastructure level.
  • Backups and available workspace export tools. Ask us to confirm the current schedule, retention, and recovery process.
  • An audit log for supported actions, including the actor, time, and affected record.
  • Supported CSV and workspace exports so your organization can retrieve its information.

Sub-processors

The services we rely on.

We rely on service providers to operate NestPoint. Payments are processed through Stripe; NestPoint does not store full card numbers in its application database. For more about the information we collect and share, see our Privacy Policy.

Questions about security?

We're happy to review current controls, documentation, and open questions with your team or board.