Where your data lives
Your data is stored in a managed Postgres database on Supabase, which also handles sign-in. The web app is hosted on Netlify. Both providers maintain SOC 2 Type II reports for their own infrastructure. Nautilus itself doesn't currently hold a SOC 2, ISO 27001, or HIPAA certification.
Encryption
Every connection to Nautilus uses HTTPS, and the app sends HSTS headers so browsers never fall back to plain HTTP. Data at rest is encrypted by our database provider.
Organization isolation
Each record in Nautilus belongs to an organization. Row-level security policies in the database make sure people can only read and change data in organizations they're a member of — the rule is enforced by Postgres, not just by the app.
Sign-in and access
Sign-in is handled by Supabase Auth, so passwords are never stored in plain text. Any account can turn on two-factor authentication with an authenticator app. What each person can do is controlled by their role (owner, admin, or member) and granular permissions, and members can be removed at any time.
API keys
API keys are displayed once when you create them and stored only as SHA-256 hashes. Each key belongs to one organization and is limited to the scopes you grant it, and API requests are rate limited.
Activity logging
Nautilus records important changes in an audit log, including who made them and when, so you can trace what happened to your inventory.
AI features
Plain-English search, forecast summaries, and anomaly explanations send the relevant records to an AI provider under its API terms to generate a result. We don't use your data to train AI models.
Security questions
If your team needs a security questionnaire completed, or you've found a vulnerability, email hello@nautilusinventory.com with “Security” in the subject line and we'll respond directly.