Skip to main content

HomeCompare approachesSee the offer

Trust and security

This page is the procurement checklist to send to security / IT / purchasing. It summarises practices reflected in the product. It does not replace a contractual questionnaire, a signed DPA, or your own risk assessment.

Authentication, SSO and roles

Workspace access uses authenticated sessions (magic link or bootstrap). Organisations can configure SAML SSO when that capability is enabled for the deployment.

Application roles: admin (configuration, billing, SSO), member (sessions, review, imports as permitted), viewer (read-only). Sensitive actions (ERP connectors, webhooks, SSO admin) are restricted to authorised roles.

Financial data, retention and ERP

General ledger lines and reconciliation artefacts (proposals, decisions, exports) are stored per organisation in the application database. ERP OAuth tokens are encrypted at rest before persistence.

Retention: data remains available for the life of the contract / organisation; deletion or export on request at end of relationship per the DPA. Use least-privilege ERP apps and rotate secrets per your policy.

Email and payments

Transactional email (magic links, Pilot ops notifications) goes through Resend. Card payments and Stripe subscriptions / quotes are processed by Stripe; Ninon does not store full card numbers. Invoice entitlements can be activated outside self-serve checkout when the contract provides for it (Pilot, Workspace).

Subprocessors (public overview)

Typical subprocessors when configured: Stripe (payments), Resend (email), PostHog (product analytics, if enabled), file storage (e.g. Vercel Blob, if enabled), application host and PostgreSQL for the deployment.

Exact residency (cloud region) depends on hosting configuration — request the current sheet from your contact. Full list and DPA: procurement / NDA phase.

Procurement checklist

  • Cloud hosting + per-organisation database — region to confirm
  • DPA / terms — internal outline available; legal version attached to quotes
  • SAML SSO — when enabled
  • Roles admin / member / viewer
  • ERP tokens encrypted at rest
  • Session reconciliation-pack export (CSV / PDF: amounts, unmatched lines, author, hash)
  • No SOC 2 / ISO marketing badges — NDA materials if available
  • Commercial entry: Close Pilot (not Essentiel card checkout for multi-entity groups)

What this page is not

We do not publish marketing-only compliance badges. Ninon does not replace ERP or consolidation. For SOC 2, ISO, pen-tests or detailed architecture, rely on materials provided under NDA during procurement.

Procurement FAQ

Does Ninon replace my ERP or consolidation tool?
No. Ninon ingests general ledger lines for intercompany reconciliation. ERP and consolidation remain your statutory systems of record. Proposed journals are exportable; Ninon does not post to the ERP.
Where is financial data stored?
Per organisation in the Ninon application database. ERP OAuth tokens are encrypted at rest. Exact cloud region depends on hosting — confirm during procurement.
Does Ninon display SOC 2 or ISO badges?
Not on the public site. For SOC 2, ISO or NDA reports, request up-to-date materials from your sales or security contact.
Which subprocessors handle data?
Depending on configuration: Stripe (payments), Resend (email), optionally PostHog (analytics), file storage and the deployment host / PostgreSQL. Contractual list in the DPA.
Which roles and SSO?
Admin, member and viewer roles. SAML SSO is configurable when the feature is enabled on the environment.
How do we start without a group card subscription?
Via a Close Pilot (quote / engagement) or limited CSV freemium. Essentiel self-serve is a 2–5 entity teaser, not the group procurement path.