Security & Compliance

At Nobili, we understand that our benchmarking insights are only as valuable as the trust you place in us. Protecting your organization's sensitive HR, payroll, and benefits data is our highest priority.

Our Compliance Framework

We align our internal controls with the most rigorous industry standards to protect Personal Health Information (PHI) and Personally Identifiable Information (PII).

HIPAA Compliant

We maintain strict administrative, physical, and technical safeguards to ensure the confidentiality of all healthcare- related documentation in accordance with the Health Insurance Portability and Accountability Act.

SOC 2 Type II Standards

Our systems are designed to meet SOC 2 criteria for security, availability, and confidentiality, ensuring that our internal processes are audited and verified.

Financial Grade Security

We treat your payroll and tax data with the same level of scrutiny as major banking institutions, adhering to best practices for financial data integrity.

How We Protect Your Data

FeatureOur Security Protocol
Data Encryption
All data is encrypted at rest using AES-256 and in transit via TLS 1.2+ (SSL) to prevent unauthorized interception.
Secure Uploads
Our proprietary portal uses secure, authenticated channels, eliminating the need for risky email-based data exchanges.
Access Control
We follow the "Principle of Least Privilege." Only essential personnel with multi-factor authentication (MFA) can access anonymized datasets.
Data Anonymization
During the benchmarking process, sensitive identifiers are scrubbed to ensure comparisons are performed on a purely aggregate basis.

Additional Security Measures

Regular Security Audits

We conduct regular third-party security audits and penetration testing to identify and address vulnerabilities proactively.

Employee Training

All team members undergo comprehensive security and privacy training to ensure they understand their role in protecting your data.

Incident Response Plan

We maintain a comprehensive incident response plan to quickly address any potential security events and minimize impact.

Data Retention Policy

We retain data only as long as necessary for business purposes and securely delete it when no longer needed.

Your Privacy Matters

We never sell, share, or misuse your data. Your information is used solely to provide you with accurate PEO comparisons and recommendations. We are committed to transparency in how we collect, use, and protect your information.