Security &
Sovereignty.
Notomir is engineered for the stringent requirements of housing authorities, government agencies, and enterprise operations. Every layer of the stack is built with security as a first principle.
Encryption & Transport
AES-256 at Rest
Documents and extracted data are stored in encrypted, AES-256 protected storage on Supabase, hosted in AWS us-east-1. Platform encryption is on by default.
HTTPS Everywhere
All data between your browser, our servers, and our AI provider travels over encrypted HTTPS connections. Every page, every upload, every download.
Cloud Infrastructure
Notomir runs on managed cloud infrastructure: Supabase (database, storage, logins) and Railway (processing). Platform-level patching and hardening are handled by the providers.
Traffic Shield
Every request to Notomir flows through Cloudflare's edge network with web-application firewall rules and rate limiting before it reaches application servers.
Regulatory Posture
Private document storage
Your documents live in a private storage bucket. There are no public links to any file. Every download goes through your signed-in account.
Audit trail
Every document view, download, filing, and client change is logged with a timestamp and the user who did it. Readable anytime from your dashboard.
Role-based access control
Agency staff, client-portal users, and platform administrators each have distinct access levels, enforced server-side on every request, not just hidden in the interface.
Data ownership
You retain full ownership of all documents and data. Download your documents anytime and export your client list from the dashboard. No lock-in.
Identity & Authorization
Google Sign-In
Sign in with your Google account alongside email and password. No extra identity provider setup required.
Verified Sessions
Every request is checked against a verified login session before data moves. Unauthenticated access to agency data is rejected at the door.
Least Privilege
Portal users see only documents matched to them. Agency data is scoped to its owner, and platform-level access is limited to the administrators who need it.
Responsible Disclosure
We take all security reports seriously. If you discover a potential vulnerability, please report it directly. Do not publicly disclose the issue until we have had reasonable opportunity to investigate and remediate.
sales@notomir.com→We acknowledge reports as quickly as possible and will keep you informed as we investigate.