generated: '2026-07-26' method: searched probe: true source: https://www.nesto.ca/security/ url: https://app.vanta.com/nesto.ca/trust/edzpx9i0szdy5sgukfq0w platform: Vanta Trust Center status: 200 certifications: - name: SOC 1 Type II scope: report on internal controls over financial reporting source: https://www.nesto.ca/security/ - name: SOC 2 Type II scope: report covering security, availability and confidentiality source: https://www.nesto.ca/security/ - name: ISO/IEC 27001:2022 scope: information security and risk management compliance source: https://www.nesto.ca/security/ encryption: in_transit: TLS 1.2 or higher at_rest: AES-256 source: https://www.nesto.ca/security/ practices: - Continuous policy updates across the organization to meet industry standards - Staff training on handling confidential data - Access controls limiting data access to authorized personnel only - Automated static analysis and manual code review - Yearly penetration testing - Hosted on Google Cloud Platform infrastructure regulatory_posture: jurisdiction: Canada claim: >- Nesto Cloud states its security architecture is "designed to meet Canadian regulatory and compliance standards of financial institutions". No specific regime (OSFI B-13, PIPEDA, Quebec Law 25) is named on any public page. source: https://nestocloud.ca/solutions/ evidence: - source: https://www.nesto.ca/security/ kind: first-party security page keywords: [SOC 1 Type II, SOC 2 Type II, ISO 27001:2022, AES-256, TLS 1.2, penetration testing] - source: https://app.vanta.com/nesto.ca/trust/edzpx9i0szdy5sgukfq0w kind: trust center (Vanta-hosted) note: >- Reachable (HTTP 200) but rendered client-side; the document list and control detail are not available to an anonymous non-JS fetch. Certification names above are taken from the first-party nesto.ca/security/ page, not from the Vanta SPA. - source: https://nestocloud.ca/solutions/ kind: product marketing keywords: [SOC 2 Type II compliance for enterprise-grade security and reliability] note: >- This is a genuine, named, third-party-audited compliance posture — unusually strong for a provider with no public API surface at all. The compliance program is published for enterprise lender buyers, not for developers.