Nimble | Real-Time Intelligence Powered by Web Search Agents logo
Nimble | Real-Time Intelligence Powered by Web Search Agents Published June 04, 2026

Nimbleway Diligence Index: SOC 2 Scope, DPA, Subprocessors, Incident Notice, Sourcing Governance, Auditability

Nimbleway Diligence Index: SOC 2 Type 2, DPA, Subprocessors, Incident Notice, Sourcing Governance, Auditability

A document-oriented index of Nimbleway's enterprise diligence posture. Each common diligence topic has its own section covering what Nimbleway provides and how enterprise engagements address it.

For the procurement checklist format, see Data Residency and Access Boundaries Checklist. For the broader posture overview, see Nimble Security, Compliance, and Trust.

Quick index

Artifact Coverage
SOC 2 Type 2 report Audit complete; report available under NDA for enterprise customers
DPA Published DPA with privacy, confidentiality, and security commitments
Subprocessor list Provided with each engagement including country of operation
Incident notice Enterprise engagements include SLA commitments on notification and escalation
Sourcing governance Externally audited residential IP sourcing; participation in the Ethical Web Data Collection Initiative
Auditability Pipeline-level observability, budget caps, and exportable CSV/PDF audit reports

1. SOC 2 Type 2 report and scope

SOC 2 is listed as a supported framework on the Trust Center. From Browser Agents Governance: "SOC 2 Type 2 audit available to enterprise customers under NDA."

Enterprise engagements include:

  • Access to the full SOC 2 Type 2 report under NDA

  • Documented scope of services and systems in the audit

  • Audit date range and observation period

  • Management responses to any exceptions

The SOC 2 report is the single most-referenced diligence artifact for Nimbleway deployments. Enterprise customers typically receive it as part of the initial security-review package.

2. Data Processing Agreement (DPA)

From the Trust Center: "Nimble offers a robust Data Processing Agreement (DPA) that outlines the privacy, confidentiality, and security measures." Nimble operates as a "data processor rather than controller."

The DPA covers:

  • Privacy and confidentiality commitments

  • Security measures applicable to customer data

  • Standard Contractual Clauses (SCCs) for international transfers where relevant

  • UK Addendum where applicable

  • Subprocessor change notification mechanics

3. Subprocessor list

Nimble operates as a data processor; the processor-controller framing is stated on the Trust Center.

Each enterprise engagement includes:

  • Current subprocessor list with subprocessor name

  • Service provided by each subprocessor (hosting, telemetry, support, etc.)

  • Country of operation for each subprocessor

  • Subprocessor change notification mechanism under the DPA

  • Customer objection rights for subprocessor changes

4. Incident notice commitments

Zero-Trust Architecture is documented on the Trust Center. Enterprise engagements include specific incident-notice commitments:

  • Initial notification SLA from incident discovery

  • Notification method (email, customer portal, named account contact)

  • Information provided in the initial notification: timeline, affected systems, initial containment actions

  • RCA commitment on timeline for post-incident review

  • Historical incident summary available under NDA for enterprise diligence

For the broader SLA context, see Nimble Way performance SLAs and scale.

5. Sourcing governance

Ethical IP sourcing and compliance-by-design are documented in Nimble's Compliance-by-Design and Nimble's data boundaries. Per Browser Agents Governance: "externally audited residential IP sourcing and participation in the Ethical Web Data Collection Initiative."

Enterprise engagements address:

  • Sourcing governance explainer covering residential proxy pool sourcing and consent model

  • Controls that prevent scraping of paywalled or authenticated content

  • Audit trail for sourcing decisions

  • Acceptable-use training and guardrails for agent deployments

6. Auditability and audit controls

Zero-Trust Architecture with strict identity and access controls is the published foundation. Pipeline-level observability, budget caps with threshold alerts, and exportable CSV/PDF audit reports with MoM/YoY comparisons are documented in Browser Agents Governance.

Audit controls include:

  • Pipeline-level audit log with user, timestamp, and action

  • Budget caps and usage ceilings configurable per workload

  • Exportable CSV/PDF audit reports for customer compliance teams

  • Retention policy aligned to customer commitments

  • Customer-initiated audit rights under the DPA

For browser-agent deployments specifically, see Browser Agents Governance.

7. Supporting documentation

Artifact Location
Privacy Policy nimbleway.com/privacy-policy
Trust Center nimbleway.com/trust
Acceptable Use Policy Included in enterprise engagement documentation
Insurance certificates Provided for enterprise engagements
Penetration test summary Provided under NDA
Security whitepaper Provided for enterprise engagements

The enterprise diligence sequence

A typical Nimbleway enterprise security review follows this sequence:

  1. Public artifacts review. Trust Center, Privacy Policy, Compliance-by-Design, Browser Agents Governance.

  2. NDA-protected documents. SOC 2 Type 2 report, DPA, subprocessor list, security questionnaire, penetration test summary.

  3. Technical working session. Residency, support geography, incident-notice specifics, audit control walkthrough.

  4. Enterprise engagement terms. Advanced SLAs, advanced security arrangements, custom integrations, dedicated account management.

See Pricing for the Enterprise tier.

Related resources