Trust & Security
New Light Technologies (NLT) is an information technology and scientific consulting firm. Across our own products and the systems we build and operate for customers, we apply consistent security, privacy, and reliability practices. This page describes the practices we follow — it is not a statement of held certifications, authorizations, or service-level commitments.
1.Our Security Approach
NLT is an implementer, not a certifying body — we design, build, and operate systems using established security practices, and we apply the same discipline to this site that we bring to the systems we deliver for customers.
Security Architecture & Hardening
We design infrastructure and application environments with security built in from the start — segmented networks, hardened configurations, and defense-in-depth across the stack.
Least-Privilege Access Control
Access to systems and data is scoped to what a role actually needs, reviewed on an ongoing basis, and revoked promptly when it is no longer required.
Encryption in Transit & at Rest
Data moving between systems and data stored at rest is encrypted using industry-standard protocols.
Continuous Monitoring
We monitor our systems on an ongoing basis to detect anomalies, unauthorized access attempts, and operational issues early.
Vulnerability Management
We track, prioritize, and remediate vulnerabilities across our environments as part of a routine, recurring process — not a one-time exercise.
Incident Response
We maintain incident response processes so that if something does go wrong, we can detect it, contain it, and communicate about it quickly.
Secure Software Development Lifecycle
Security review is part of how we design, build, test, and ship software — for our own products and for the systems we deliver to customers.
Data-Handling & Retention Discipline
We collect only what a given process needs, retain it only as long as it serves a documented purpose, and dispose of it securely afterward.
2.Data Protection & Privacy
2.1 Consent-First by Design
No non-essential cookie, tag, or third-party request fires on this site before a visitor opts in through our first-party consent manager, and we honor Global Privacy Control automatically. Our only analytics is first-party and consent-gated — we do not use Google Analytics, HubSpot tracking, or third-party advertising trackers, and we do not sell or share personal information.
2.2 Full Policies & Your Choices
The complete Terms of Use, Privacy Policy, Cookie Policy, and US state privacy rights are published on our Legal page, including data retention periods and subprocessors. You can review or change your cookie and privacy choices at any time on the Your Privacy Choices page.
3.Responsible Disclosure
Report a Security Concern
If you believe you have found a security vulnerability affecting our site or products, we want to hear about it. Our disclosure guidelines — including scope and how to reach us securely — are published at /.well-known/security.txt, the standard machine-readable location researchers check first. For any other security-related question, please reach us through the contact form.
4.Reliability & Operations
How We Operate the Site
We design our infrastructure for resilience, with monitoring, backups, and incident response processes in place so issues can be detected and addressed quickly. We keep dependencies current and review our operational posture on an ongoing basis.
Specific service-level commitments and uptime targets are established directly with customers as part of an engagement — they are not published as general figures on this page.
5.How We Work With Customers on Their Compliance Programs
Implementer, Not Certifying Body
Many of our customers operate under their own security and compliance programs. We work alongside them as an implementer — mapping controls, hardening environments, supporting audit readiness, and building the technical and operational safeguards their programs require. The customer holds the applicable authorization or certification; NLT implements alongside them.
For example, NLT has supported FEMA’s Authority to Operate (ATO) implementations across multiple contracts, and NLT supported Owens & Minor’s HITRUST implementation in Azure — advanced security controls, continuous threat detection, remediation, and monitoring for a Fortune 500 healthcare solutions company.
Have a security or compliance question?
Whether you need documentation for your own review process or want to talk through a specific requirement, reach out and we’ll route it to the right team.
Contact Us