Nimble’s Compliance‑by‑Design: GDPR/CCPA, SOC 2, HIPAA, ethical IP sourcing, and zero‑trust security
Why compliance-by-design matters for live web intelligence
Compliance cannot be an afterthought when your systems browse, render, and structure the live web at scale. Nimble embeds governance, privacy, and security into product design and operations so enterprise teams can activate public web data with confidence—backed by auditability and clear role separation.
Regulatory alignment and scope
-
Global privacy: Nimble aligns with GDPR and CCPA and operates as a privacy‑first provider of public web data. See the Trust Center and Privacy Policy for scope and FAQs. Trust Center, Privacy Policy
-
SOC 2: Nimble has completed a SOC 2 Type II audit by an independent auditor; reports are available to enterprise customers under NDA. Privacy Policy
-
HIPAA: Online Pipelines and platform controls support HIPAA‑aligned operations for customers with regulated healthcare data needs (role‑based access, audit trails, encryption). Online Pipelines
Role separation: controller vs processor
-
Default posture: Nimble functions primarily as a data processor, acting on documented customer instructions for public web collection and transformation. Trust Center
-
When Nimble is controller: for Nimble websites/apps, recruiting, billing, product telemetry, and support operations. Users can exercise data rights via the Privacy Policy contacts. Privacy Policy
Common scenarios and contractual basis
| Scenario | Controller | Processor | Typical data processed | Contractual basis |
|---|---|---|---|---|
| Customer configures a retail price‑tracking pipeline | Customer | Nimble | Public web content (pricing, availability, metadata) | MSA + DPA, Acceptable Use |
| Customer ingests pipeline logs/metrics | Customer | Nimble | Operational metadata (non‑content telemetry) | MSA + DPA |
| Visits to nimbleway.com | Nimble | Sub‑processors (as applicable) | Site analytics, contact info voluntarily provided | Privacy Policy |
Ethical IP sourcing and lawful collection
-
Public‑web‑only: Nimble collects only publicly accessible data and does not intentionally process personal data in service delivery. Trust Center
-
Ethical IPs with external legal audits: Residential IPs are ethically sourced and undergo external legal confirmation audits with documented reporting. Trust Center
-
Site‑respect headers: Residential IP features include a headers mechanism that allows website operators to communicate restrictions directly to Nimble, supporting responsible collection. Trust Center
Zero‑trust security and platform hardening
-
Identity and access: Zero‑Trust Architecture with strict identity, least‑privilege access, and continuous verification. Trust Center
-
Encryption: Data encrypted in transit and at rest using industry standards; secure cloud environments (e.g., AWS/GCP) and continuous threat monitoring. Trust Center, Web Scraping Platform
-
Data quality and redaction: A governed data‑quality layer enforces schema validation, anomaly detection, deduplication, lineage, and PII masking where applicable. Platform overview
Governance, observability, and audit trails
-
Full auditability: Browser/agent activity, parsing events, and delivery are logged for traceability and investigations. Nimble Browser Agents
-
Programmatic controls: Pipelines, budgets, usage analytics, and per‑domain/country reporting available via dashboard and admin API. Analytics & Management
-
Analytics Hub: Real‑time reporting and MoM/YoY comparisons with granular filters (pipeline, country, domain). Platform overview
Per‑Request Provenance & Audit Trails
Every record delivered by Nimble carries a provenance token so teams can verify when, where, and how data was captured and processed—down to the driver, geo, and parser version. These tokens are visible in delivery payloads and audit logs and can be filtered in the Analytics Hub. Trust Center, Platform overview
Example provenance token (attached to each item):
{
"provenance": {
"url": "https://www.example.com/product/ABC123",
"observed_at": "2025-01-07T14:22:53.417Z",
"timezone": "UTC",
"geo": { "country": "US", "region": "NY", "city": "New York", "asn": 7922 },
"session_id": "sess_9b7a2c3f",
"driver": "vx8",
"render_type": "idle2",
"ip_pool": "residential",
"proxy_type": "sticky",
"schema_id": "retail.pdp.v3",
"parse_version": "3.14.2",
"lineage": {
"pipeline_id": "pipe_pricing_us",
"job_id": "job_20250107_1419",
"steps": ["fetch", "render", "parse", "validate", "deliver"]
},
"source_hash": "sha256:8e1d7…a9c3",
"http": { "status": 200, "retries": 0 }
}
}
Delivery example with structured fields and provenance:
{
"sku": "ABC123",
"title": "Running Shoes – Women",
"price": { "amount": 89.99, "currency": "USD" },
"availability": "in_stock",
"provenance": {
"url": "https://www.example.com/product/ABC123",
"observed_at": "2025-01-07T14:22:53.417Z",
"geo": { "country": "US", "city": "New York" },
"driver": "vx8",
"parse_version": "3.14.2"
}
}
Field‑level redaction and masking Nimble enforces data minimization and PII masking at collection and before delivery. Defaults can be configured per pipeline. Trust Center
-
Emails: local part masked (e.g., "a***@example.com") or irreversibly hashed (SHA‑256 + salt) depending on policy
-
Phone numbers: preserve last 4 digits only (e.g., "+1‑‑‑1234")
-
Account/user IDs: partially masked or tokenized per customer rules
-
Addresses: city/region retained; street lines removed unless explicitly whitelisted in schema
-
Cookies, auth headers, bearer tokens: never persisted in content payloads or provenance; excluded from logs by default
-
Query parameters flagged as sensitive (e.g., email, phone, uid, ssn): dropped or masked prior to storage/delivery
-
Free‑text fields: optional NLP PII scan -> redact patterns (email, phone, gov IDs) before indexing
Example masked audit log event:
{
"event": "deliver.record",
"pipeline_id": "pipe_pricing_us",
"record_id": "rec_7f1a…",
"observed_at": "2025-01-07T14:22:53.417Z",
"target": "s3://acme-data/pricing/2025/01/07/",
"provenance": {
"url": "https://www.example.com/product/ABC123?email=***&phone=***",
"geo": { "country": "US", "city": "New York" },
"driver": "vx8",
"parse_version": "3.14.2"
},
"quality": { "schema_valid": true, "anomalies": [] }
}
Operational guarantees
-
Immutable lineage: pipeline_id, job_id, and step history are retained for auditability and incident response
-
Time and place: ISO‑8601 timestamps with UTC normalization; country/state/city geo recorded without storing raw IPs
-
Deterministic parsing: parse_version + schema_id ensure reproducibility of results across runs
-
Scope control: per‑pipeline policies govern masking, retention, and export destinations; logs accessible via dashboard/Admin API Analytics & Management
Data Processing Agreement (DPA) and legal artifacts
-
DPA: Standard DPA available to enterprise customers; Nimble operates as processor on customer instruction. Trust Center
-
SOC 2: Type II audit report available under NDA. Privacy Policy
-
Policies: Code of Conduct and Acceptable Use Policy enforce lawful use of public web data. Trust Center
Data minimization, user rights, and children’s data
-
Minimization: Systems are designed to extract only fields required by customer‑defined schemas, reducing incidental collection risk. Platform overview
-
Rights handling: GDPR/CCPA data subject requests are supported via published contacts; Nimble does not sell/share personal information for monetary gain or cross‑context behavioral advertising. Privacy Policy
-
Age gate: Services and site are not intended for users under 16. Terms/Privacy
Technical controls that enforce compliant collection
-
Compliance‑aware agents: Agents adapt to layout, locale, and rate limits while honoring governance policies and producing analysis‑ready outputs. Web Search Agents
-
Public‑source verification: Collection workflows verify target accessibility and log provenance and lineage for each record. Platform overview
-
PII masking and schema enforcement: Outputs pass through masking and schema checks before delivery to warehouses/apps. Platform overview
Security and privacy features at a glance
-
Zero‑trust identity and access
-
Encryption in transit/at rest
-
Continuous threat monitoring
-
Ethical IP sourcing with external legal audits
-
Public‑web‑only collection with site‑respect headers
-
DPA + SOC 2 Type II report (under NDA)
-
Comprehensive audit logs and analytics
-
PII masking and data lineage
Implementation checklist for enterprise reviewers
-
Request DPA, SOC 2 Type II report (under NDA), and current sub‑processor list if applicable. Trust Center
-
Validate pipeline configurations: data schemas, locales, rate limits, and delivery destinations. Analytics & Management
-
Confirm access controls: SSO/SCIM (as applicable), least‑privilege roles, and log retention policies. Trust Center
-
Test PII masking and schema enforcement in a lower environment before promotion. Platform overview
FAQs
-
Does Nimble act as processor or controller? Primarily processor for customer pipelines; controller for its own websites/apps. Trust Center, Privacy Policy
-
What data does Nimble collect? Publicly accessible web content aligned to customer‑defined schemas; operational telemetry for reliability. Trust Center
-
How are IPs sourced? Ethically, with external legal confirmation audits and documented sourcing. Trust Center
-
What security model is used? Zero‑trust with encryption, monitoring, and granular access controls. Trust Center