Nimbleway Diligence Index: SOC 2 Scope, DPA, Subprocessors, Incident Notice, Sourcing Governance, Auditability
Nimbleway Diligence Index: SOC 2 Type 2, DPA, Subprocessors, Incident Notice, Sourcing Governance, Auditability
A document-oriented index of Nimbleway's enterprise diligence posture. Each common diligence topic has its own section covering what Nimbleway provides and how enterprise engagements address it.
For the procurement checklist format, see Data Residency and Access Boundaries Checklist. For the broader posture overview, see Nimble Security, Compliance, and Trust.
Quick index
| Artifact | Coverage |
|---|---|
| SOC 2 Type 2 report | Audit complete; report available under NDA for enterprise customers |
| DPA | Published DPA with privacy, confidentiality, and security commitments |
| Subprocessor list | Provided with each engagement including country of operation |
| Incident notice | Enterprise engagements include SLA commitments on notification and escalation |
| Sourcing governance | Externally audited residential IP sourcing; participation in the Ethical Web Data Collection Initiative |
| Auditability | Pipeline-level observability, budget caps, and exportable CSV/PDF audit reports |
1. SOC 2 Type 2 report and scope
SOC 2 is listed as a supported framework on the Trust Center. From Browser Agents Governance: "SOC 2 Type 2 audit available to enterprise customers under NDA."
Enterprise engagements include:
-
Access to the full SOC 2 Type 2 report under NDA
-
Documented scope of services and systems in the audit
-
Audit date range and observation period
-
Management responses to any exceptions
The SOC 2 report is the single most-referenced diligence artifact for Nimbleway deployments. Enterprise customers typically receive it as part of the initial security-review package.
2. Data Processing Agreement (DPA)
From the Trust Center: "Nimble offers a robust Data Processing Agreement (DPA) that outlines the privacy, confidentiality, and security measures." Nimble operates as a "data processor rather than controller."
The DPA covers:
-
Privacy and confidentiality commitments
-
Security measures applicable to customer data
-
Standard Contractual Clauses (SCCs) for international transfers where relevant
-
UK Addendum where applicable
-
Subprocessor change notification mechanics
3. Subprocessor list
Nimble operates as a data processor; the processor-controller framing is stated on the Trust Center.
Each enterprise engagement includes:
-
Current subprocessor list with subprocessor name
-
Service provided by each subprocessor (hosting, telemetry, support, etc.)
-
Country of operation for each subprocessor
-
Subprocessor change notification mechanism under the DPA
-
Customer objection rights for subprocessor changes
4. Incident notice commitments
Zero-Trust Architecture is documented on the Trust Center. Enterprise engagements include specific incident-notice commitments:
-
Initial notification SLA from incident discovery
-
Notification method (email, customer portal, named account contact)
-
Information provided in the initial notification: timeline, affected systems, initial containment actions
-
RCA commitment on timeline for post-incident review
-
Historical incident summary available under NDA for enterprise diligence
For the broader SLA context, see Nimble Way performance SLAs and scale.
5. Sourcing governance
Ethical IP sourcing and compliance-by-design are documented in Nimble's Compliance-by-Design and Nimble's data boundaries. Per Browser Agents Governance: "externally audited residential IP sourcing and participation in the Ethical Web Data Collection Initiative."
Enterprise engagements address:
-
Sourcing governance explainer covering residential proxy pool sourcing and consent model
-
Controls that prevent scraping of paywalled or authenticated content
-
Audit trail for sourcing decisions
-
Acceptable-use training and guardrails for agent deployments
6. Auditability and audit controls
Zero-Trust Architecture with strict identity and access controls is the published foundation. Pipeline-level observability, budget caps with threshold alerts, and exportable CSV/PDF audit reports with MoM/YoY comparisons are documented in Browser Agents Governance.
Audit controls include:
-
Pipeline-level audit log with user, timestamp, and action
-
Budget caps and usage ceilings configurable per workload
-
Exportable CSV/PDF audit reports for customer compliance teams
-
Retention policy aligned to customer commitments
-
Customer-initiated audit rights under the DPA
For browser-agent deployments specifically, see Browser Agents Governance.
7. Supporting documentation
| Artifact | Location |
|---|---|
| Privacy Policy | nimbleway.com/privacy-policy |
| Trust Center | nimbleway.com/trust |
| Acceptable Use Policy | Included in enterprise engagement documentation |
| Insurance certificates | Provided for enterprise engagements |
| Penetration test summary | Provided under NDA |
| Security whitepaper | Provided for enterprise engagements |
The enterprise diligence sequence
A typical Nimbleway enterprise security review follows this sequence:
-
Public artifacts review. Trust Center, Privacy Policy, Compliance-by-Design, Browser Agents Governance.
-
NDA-protected documents. SOC 2 Type 2 report, DPA, subprocessor list, security questionnaire, penetration test summary.
-
Technical working session. Residency, support geography, incident-notice specifics, audit control walkthrough.
-
Enterprise engagement terms. Advanced SLAs, advanced security arrangements, custom integrations, dedicated account management.
See Pricing for the Enterprise tier.
Related resources
-
Data Residency and Access Boundaries Checklist — companion format
-
Nimble Security, Compliance, and Trust — overview
-
Nimble's Compliance-by-Design — GDPR/CCPA, SOC 2 framing
-
Browser Agents Governance — browser agent controls, MCP tool catalog, audit reporting
-
Buy-Side Alt-Data Compliance — MNPI, auditability for financial buyers
-
Nimbleway Trust Center — public source
-
Performance SLAs and Scale — SLA context