Data protection
Encryption at rest, in transit, and governed deletion
OperatingRead statementA living, public statement of the firm’s own security and compliance posture, because a firm that sells security must visibly hold itself to the standard it asks of others.
Public commitments backed by internal ownership, review, and a monitored disclosure route.
A firm that sells security must be the first to practise it.
Firms that sell vigilance while practising very little of it on themselves. The Trust Center is the firm’s refusal of that hypocrisy, made public. It states openly how Namlameis protects its own systems, the data its clients entrust to it, and the integrity of every engagement, encryption, access control, compliance posture, and a responsible-disclosure channel for anyone who finds a flaw in the firm itself.
For the buyers who matter most, in finance, in government, in critical infrastructure, this page is not marketing. It is a precondition. A firm that cannot answer “how do you secure yourselves” will never pass their vendor review, and the Trust Center answers it before they have to ask.
Each statement is written plainly, attached to an operating discipline, and kept visible so trust does not depend on a private sales conversation.
Encryption at rest, in transit, and governed deletion
OperatingRead statementLeast privilege, reviewable access, and strong authentication
EnforcedRead statementContinuity, recovery, and monitored service dependencies
MaintainedRead statementA monitored route for good-faith security research
OpenRead statementEncryption in transit and at rest, and secure-deletion practice, described plainly.
Least-privilege access and full audit logging across the firm’s own systems.
Alignment to the GDPR and the Austrian Data Protection Act, kept current.
A clear, monitored channel for anyone who finds a security issue in the firm.
Compliance is not presented as a collection of badges. Each obligation points to the control, owner, evidence, and review cycle that makes the commitment real.
Good-faith security research deserves a monitored channel, a timely acknowledgement, and clear expectations for coordinated resolution.
Encrypted contact and a clear scope protect both the reporter and the investigation.
The report enters a monitored security workflow rather than a general inbox.
Impact, fix, validation, and public timing remain connected throughout.
Material changes to controls, availability, and public commitments should remain visible over time—not disappear when a page is rewritten.
Review the public posture or request the evidence appropriate to your organisation.