Stop spending weeks mapping skills, defining roles & building career paths. Nestor AI does it in seconds.
read more
Success Stories
View Plans

Nestor Is Now SOC 2 Type II Certified

5 min read

Nestor Is Now SOC 2 Type II Certified

Enterprise organizations expect every platform they adopt to protect their data, withstand operational disruption, and meet rigorous security standards. For systems that inform decisions about people, skills, and workforce strategy, those expectations are non-negotiable.

Nestor is now SOC 2 Type II certified, reinforcing our commitment to maintaining the security controls and operational practices required by enterprise organizations.

Built on the Trust Services Criteria of the American Institute of Certified Public Accountants (AICPA), the SOC 2 Type II examination assesses whether a company’s controls are properly designed and whether they perform consistently over an extended period.

For our customers and partners, it is independent confirmation that security is part of how Nestor is built, operated, and governed, and a commitment we will continue to uphold.

What SOC 2 Type II certification is

A SOC 2 Type II examination is a formal, evidence-based assessment of how a service provider protects the data entrusted to it. A licensed CPA firm reviews the provider’s controls across areas such as access management, change management, system monitoring, and incident response, and tests each one against records collected throughout the observation period. The findings are issued in a formal report that customers can review as part of their own vendor due diligence.

For enterprise security, risk, and procurement teams, the Type II report carries particular weight. It shows how controls perform in live operation, across platform releases, organizational change, and production workloads, which is why it is commonly required in enterprise vendor risk assessments.

With this certification, Nestor has demonstrated:

  • Verified operational security. Nestor’s controls were tested against evidence from across the audit period and confirmed to operate as designed, protecting customer data from unauthorized access.
  • Disciplined governance of sensitive data. The examination assessed how customer data is accessed, stored, and shared within the platform, a critical safeguard for the people and workforce data Nestor manages.
  • Independent accountability. Nestor’s security practices are measured against the AICPA Trust Services Criteria and attested by an independent auditor with no stake in the outcome.

What this means for our customers

SOC 2 Type II certification delivers clear benefits to the organizations that work with Nestor:

  • Faster security reviews: The SOC 2 Type II report answers most of a standard vendor security assessment in a single document. Procurement moves forward without weeks of questionnaires and follow-up calls.
  • Support for your own compliance: When your auditors, regulators, or data protection team ask how third-party vendors handle employee data, you have independent evidence to share. The report supports your GDPR accountability and vendor risk management processes
  • More focus on the work that matters: With security independently verified, HR teams can spend less time chasing assurances about where their data lives. That time goes back into using skills data to plan, develop, and deploy talent.

A security-first approach to workforce data

Nestor manages some of the most business-critical information an enterprise holds: skills profiles, performance reviews, engagement signals, career histories, and development plans. Together, this data informs decisions on workforce planning, succession, internal mobility, and talent investment, and it demands the same level of protection as any other critical business system.

We approach that responsibility with a security-first mindset. Protection is designed into the platform from the start, our systems are hardened against unauthorized access, and our security priorities are set by a clear understanding of where the risk to customer data sits. SOC 2 Type II certification validates that approach, giving HR, IT, and security leaders independent evidence they can present to their risk committees and executive teams.

Security has been a first principle at Nestor from day one. We harden our platform, focus our controls on what matters most to our customers, and build every capability with security in mind. SOC 2 Type II gives enterprise organizations independent verification of that approach.

— Bogdan Apostol, CEO at Nestor
Bogdan Apostol, CEO at Nestor

A standard we maintain

A SOC 2 Type II report reflects a defined set of criteria assessed over a defined period. Nestor is committed to sustaining that standard every day: our controls are monitored continuously between reporting cycles, and the report is renewed on a regular basis, so the assurance our customers rely on always reflects how Nestor operates today.

Nestor connects with the HR and business systems teams already use, brings AI into everyday talent workflows while keeping people in charge of consequential decisions, and now carries independent verification that the data behind it all is secure.

Requesting the report

Nestor’s SOC 2 Type II report is available to customers and prospects under NDA, usually as part of a security or procurement review.

If you are an existing Nestor customer, you can request a copy of our SOC 2 Type 2 report directly through your assigned Customer Success Manager. If you are not currently a customer, or do not have a designated Nestor contact, you can submit a request using the form below. If your team is preparing a vendor assessment, this report is built to answer most of what you will need in a single document, which tends to save everyone a few rounds of back-and-forth.

Make smart, fast, and confident decisions with Nestor's skills-based talent management solutions
Doodle

Make smart, fast, and confident decisions with Nestor's skills-based talent management solutions