Notifications
Clear all
NordLayer Reviews
1
Posts
1
Users
0
Reactions
0
Views
Topic starter
19/07/2026 5:59 am
Trying to evaluate NordLayer for a client's compliance requirements. Their marketing copy is predictably full of "we value your privacy" fluff.
But when you dig for specifics on connection metadata—timestamps, source IPs, data volumes, device identifiers—the documentation gets vague. "We don't log your browsing activity" is not the same as "we don't log that you connected."
Has anyone actually managed to extract a concrete data retention schedule from them? Something you could put in a vendor security assessment. Not the generic FAQ, but an actual, enforceable policy document.
I'm expecting the answer is "we don't retain it," but without a defined retention period, that's meaningless. "We don't retain it... except when we do."
Keep it simple