Skip to content
Trust Center

We practise what we sell.

A living, public statement of the firm’s own security and compliance posture, because a firm that sells security must visibly hold itself to the standard it asks of others.

Public commitmentsNamed ownershipReviewable evidence
Public assurance recordOperational
Security postureControls stated.
Evidence retained.

Public commitments backed by internal ownership, review, and a monitored disclosure route.

Data protectionEncryption at rest, in transit, and governed deletionOperatingIdentity & accessLeast privilege, reviewable access, and strong authenticationEnforcedOperational resilienceContinuity, recovery, and monitored service dependenciesMaintainedResponsible disclosureA monitored route for good-faith security researchOpen
Last reviewedCurrent posture verifiedReview continuous
Practice before promise

A firm that sells security must be the first to practise it.

A firm that sells security must be the first to practise it.

Firms that sell vigilance while practising very little of it on themselves. The Trust Center is the firm’s refusal of that hypocrisy, made public. It states openly how Namlameis protects its own systems, the data its clients entrust to it, and the integrity of every engagement, encryption, access control, compliance posture, and a responsible-disclosure channel for anyone who finds a flaw in the firm itself.

For the buyers who matter most, in finance, in government, in critical infrastructure, this page is not marketing. It is a precondition. A firm that cannot answer “how do you secure yourselves” will never pass their vendor review, and the Trust Center answers it before they have to ask.

Public security posture

The commitments a serious buyer should never have to chase.

Each statement is written plainly, attached to an operating discipline, and kept visible so trust does not depend on a private sales conversation.

Control statement

Data protection

Encryption at rest, in transit, and governed deletion

OperatingRead statement
Control statement

Identity & access

Least privilege, reviewable access, and strong authentication

EnforcedRead statement
Control statement

Operational resilience

Continuity, recovery, and monitored service dependencies

MaintainedRead statement
Control statement

Responsible disclosure

A monitored route for good-faith security research

OpenRead statement
Control statements

Trust becomes useful when the underlying practice is legible.

Protection discipline

Data protection, stated

Encryption in transit and at rest, and secure-deletion practice, described plainly.

Protection discipline

Access & audit

Least-privilege access and full audit logging across the firm’s own systems.

Public assurance

Compliance posture

Alignment to the GDPR and the Austrian Data Protection Act, kept current.

Public assurance

Responsible disclosure

A clear, monitored channel for anyone who finds a security issue in the firm.

Compliance mapping

Framework language mapped to operating reality.

Compliance is not presented as a collection of badges. Each obligation points to the control, owner, evidence, and review cycle that makes the commitment real.

ObligationWhat the framework requiresControlHow the requirement is implementedEvidenceWhat demonstrates operation
Control mappingEvidence linked
GDPRAustrian DSGDORANIS2
  • Data protection by designEncryption & access governanceMapped
  • Integrity and confidentialityAudit, monitoring & incident responseMapped
  • Rights and retentionDeletion and review workflowMapped
Evidence is available to qualified reviewersRequest package
Responsible disclosure

If you find a weakness, there is a responsible route in.

Good-faith security research deserves a monitored channel, a timely acknowledgement, and clear expectations for coordinated resolution.

ReportShare the minimum evidence needed

Encrypted contact and a clear scope protect both the reporter and the investigation.

AcknowledgeA human confirms ownership

The report enters a monitored security workflow rather than a general inbox.

ResolveCoordinate remediation and disclosure

Impact, fix, validation, and public timing remain connected throughout.

Transparency record

A living posture, not a one-time declaration.

Material changes to controls, availability, and public commitments should remain visible over time—not disappear when a page is rewritten.

CurrentControl posture reviewedPublic statements and ownership confirmed
MaintainedResponsible-disclosure route testedMonitoring and acknowledgement workflow verified
PublishedCompliance mapping refreshedEuropean regulatory obligations linked to controls
Assurance before procurement

Pass the vendor review before it begins.

Review the public posture or request the evidence appropriate to your organisation.