Nelum

Security & data

Built so your documents stay yours

You are being asked to put incorporation documents, ownership structures and passports into someone else's platform. Here is exactly where they go, who can reach them, and how long they stay — answered before your compliance team has to ask.

You keep control of your own funds, start to finish

Money moves between wallets you and your counterparty control, on your own timing, under your own keys. Nelum’s part is to read the chain and confirm that the transfer you described actually happened.

There is no Nelum wallet in the middle of your trade, no private key we could lose, and no balance we could freeze. The other side of that independence is that a transfer sent to a wrong or fraudulent address cannot be reversed by us — the security of your own wallet stays with you.

Settlement is conducted directly between counterparties using non-administered escrow — funds move between wallets the counterparties themselves control. Nelum does not hold, control, custody, transmit, or have any power to move client funds or private keys at any time. Nelum's role in settlement is limited to read-only verification that a transfer the counterparties describe has occurred on-chain.

Six controls, and what each one gives you

Each of these is enforced by the system rather than promised by a policy, which is the difference that matters when you are deciding whether to upload a passport.

Your verification documents have no read path

Incorporation certificates, ownership registers and identity documents go into private storage the platform cannot read back. Once submitted they cannot be downloaded again — by anyone, including the company that submitted them and including us. There is nothing to leak through the product surface, because there is no surface.

Your access rules live in the database

Row-level security governs every read. Your company sees its own records and the orders it is party to; trade documents are visible to the two counterparties on that order. It is enforced beneath the application, so a missing check in a page cannot widen it.

Your face is served by short-lived link only

Representative photographs are held privately and served through signed links that expire, including on the public credential page. There is no permanent public URL for anyone's face — the QR a counterparty scans resolves through us each time.

You choose when your legal name is disclosed

On the marketplace you are a pseudonymous reference with your country and verification status. Legal names are exchanged when both sides enter an order — so you can browse, post and compare without publishing what your company is buying.

Every action carries a name and a time

Document uploads, requests, message edits, role changes and verification decisions are all recorded with the actor and the timestamp. Governance events record which fields changed and never the values, so the trail proves a change occurred without becoming a second copy of your data.

Your retention period is stated, not assumed

Verification and transaction records are kept for the periods anti-money-laundering law requires — at least five years after the end of the relationship. Where that obligation applies we tell you it applies, rather than quietly keeping data or quietly deleting evidence.

Measured against standards you can go and read

We did not invent our own definition of verified.

Identity and business verification

KYB on the company, KYC on the people who can act for it, sanctions and PEP screening, and biometric liveness tested against presentation attacks under ISO/IEC 30107 rather than assumed safe — to SOC 2 Type II, ISO/IEC 27001 and the eIDAS/ETSI standards for remote identity proofing at a high level of assurance.

Where the record lives

Row-level authorisation, AES-256 at rest, TLS in transit, ISO/IEC 27001:2022 and SOC 2 Type 2, audited annually over an observation window rather than on one good day.

Stated precisely: these are the standards our verification and our record are built and audited against. They are named so that you can go and read what each one requires, rather than take our word for it — and because they expire, so somebody has to keep passing them.

Your rights over your data

You can access, correct and port your personal data, and withdraw consent where processing rests on it — including consent to publish a representative's photograph on their credential page. Withdrawing that consent removes the photograph from public view.

Where anti-money-laundering law requires us to retain a verification record, that obligation takes precedence over a deletion request. We will restrict the record to meeting the legal obligation and tell you we have done so. The full detail is in our Privacy Notice.

Questions before you register?

If your compliance or security team needs detail we have not published here, ask us directly and we will answer it.

Contact us