Security at Nation
Our commitment
Protecting the data our customers trust us with is foundational to Nation. We build security into our infrastructure, our software, and our day-to-day operations, and we review those practices on an ongoing basis.
NationApp is currently undergoing a SOC 2 Type II examination. A report will be made available to prospects and customers under NDA upon completion.
Data encryption
- In transit: All data exchanged with Nation is encrypted using TLS 1.2 or higher. Connections are served over HTTPS, and unencrypted connections are redirected or refused.
- At rest: Customer data is encrypted at rest using AES-256, including our primary databases, file/object storage, and caching layers.
Infrastructure & hosting
- Nation runs on Amazon Web Services (AWS) in the United States, allowing us to build on AWS's audited physical and environmental controls.
- Production systems run inside isolated private networks with restricted access; only the minimum necessary endpoints are exposed publicly.
- We employ continuous threat detection and monitoring across our cloud environment.
- Our web application is served over the web at gioanation.com, with our API hosted at api.gioanation.com.
- Customer data is backed up automatically on a recurring schedule, with encrypted, cross-region backup copies retained to support recovery.
Access control
- Access to production systems and customer data follows the principle of least privilege — people are granted only the access their role requires.
- Multi-factor authentication (MFA) is required for privileged access.
- We conduct periodic access reviews to confirm that access remains appropriate.
- Access is promptly revoked when an employee or contractor leaves or changes roles.
Secure development
- Changes to our software go through peer code review before release.
- We run automated scanning for vulnerable dependencies, container-image vulnerabilities, and exposed secrets. Secret scanning runs on every change; dependency and container-image scanning runs continuously against our production images.
- Every change requires review and approval before merge, and every deployment requires a separate approval. These gates are enforced in source control and cannot be bypassed by a single engineer.
- We maintain separate development, staging, and production environments, and manage our infrastructure as code for consistent, reviewable changes.
Vulnerability management & responsible disclosure
We scan our systems and dependencies for vulnerabilities on an ongoing basis and prioritize remediation based on severity. Our application has also undergone third-party penetration testing, with findings remediated based on severity.
If you believe you have found a security vulnerability in Nation, please report it to security@nationapp.com. We also publish a machine-readable contact file per RFC 9116 at https://api.gioanation.com/.well-known/security.txt.
We support good-faith security research: we will not pursue or support action against researchers who report vulnerabilities responsibly, respect the privacy of our users, and avoid degrading or disrupting our services.
Incident response
We maintain a documented incident response plan that defines how we detect, triage, and respond to security events, with severity-based prioritization. In the event of a security incident affecting customer data, we will notify affected customers without undue delay and in accordance with applicable contractual and legal obligations.
Data privacy & retention
We collect and process personal data as described in our Privacy Policy. Customers may request deletion of their data, and we honor verified deletion requests in line with that policy. Residual copies of deleted data in our encrypted backups are purged on our standard backup-expiration schedule.
Compliance
Nation is currently undergoing a SOC 2 Type II examination. Upon completion, our report will be available to prospects and customers under NDA. For compliance inquiries, contact security@nationapp.com.
Contact
For any security or privacy question, reach us at security@nationapp.com.
Last updated: August 2026.