Security

Security

Last updated: June 15, 2026

Operated by: SAGBRAIN CORPORATION

Nokoru is built to protect your organization’s knowledge above all. Information security is operated under the ISMS framework certified to our parent company, with encryption, access control, and tenant isolation implemented in depth.

1. Certification & Governance

ISMS (ISO/IEC 27001)

Information security is operated under ISO/IEC 27001 (Information Security Management System, certificate no. MSA-IS-532), held by our parent company, SAGBRAIN CORPORATION.

Group Operating Structure

Group companies entrusted with parts of development and operations — SAGBRAIN Bangladesh Co., Ltd. and Sagbrain Global Pte. Ltd. — work under the management framework of the certification above.

2. Encryption

Encryption in Transit

All traffic between your browser and our servers is encrypted with TLS.

Encryption at Rest

Data is encrypted at rest with AES-256. Uploaded files are stored encrypted on AWS S3.

3. Access Control & Tenant Isolation

Group-level Access Control

Documents and channels are scoped by group. To non-members, the documents and channels are invisible — not merely access-denied.

Full Tenant Isolation

Tenants (teams) are fully isolated at the database layer using PostgreSQL Row Level Security.

Single Sign-On (SSO)

SAML SSO and email-domain auto-join let you integrate with your organization’s identity provider.

4. Infrastructure & Data Residency

Hosting

The Service is hosted in the AWS Tokyo region.

Audit Logs

Audit logs of key operations are retained and used to detect and trace unauthorized access.

5. Reporting a Vulnerability

How to Report

If you discover a security concern or vulnerability, please contact us at info@sagbrain.com. We will review and respond promptly.

Have questions? We are happy to help.

info@sagbrain.com