# NVM for Windows Certified Builds

> Commercial NVM for Windows products for managed organizational environments.

Certified Builds are the required commercial foundation. They use an annual, site-wide license covering one Active Directory forest, or one Microsoft Entra tenant when no forest exists. Trust Artifacts, Advanced Logging, and Governance are optional add-ons.

## Annual pricing

| Product | Role | Annual price |
| --- | --- | ---: |
| Certified Builds | Required foundation | $600 / year |
| Trust Artifacts | Optional add-on | $600 / year |
| Advanced Logging | Optional add-on | $600 / year |
| Governance | Optional add-on | $3,000 / year |

Pricing is site-wide rather than per-seat. The [Certified Builds configurator](https://nvm-windows.com/certified) estimates the effective cost per user and creates a purchase configuration. Purchases are completed through the [Customer Portal](https://portal.author.io).

## Certified Builds

Certified Builds provide the managed foundation for deploying NVM for Windows across an organization.

- **IT-managed installation:** Install NVM for Windows in a Windows-protected directory so administrators can control its deployment and management on each device.
- **Organization-wide license:** Cover one Active Directory forest, or one Microsoft Entra tenant when no forest exists, with a single annual license.
- **Easy renewal and cancellation:** Receive timely email and desktop renewal notifications and cancel online through the Customer Portal.
- **Security pack and vendor risk controls:** NVM for Windows does not collect user data. An up-to-date security pack, privacy policy, EULA, and data-use limits are always available.
- **Microsoft Intune:** Deploy prepackaged Intune files through Microsoft endpoint management without maintaining a custom package.
- **MSI installer:** Use a standard Windows Installer package with an organization's existing deployment process.
- **User-controlled NVM firewall:** Let users control approved Node.js versions, npm modules, and trusted command-line tools.

## Add-ons

### Trust Artifacts — $600 / year

- **CycloneDX SBOM:** A signed software bill of materials documenting the components included in each certified release.
- **SLSA provenance:** Signed build provenance documenting where a release came from and how it was produced.
- **VEX reports:** Vulnerability Exploitability eXchange reports showing whether known vulnerabilities affect a release.

### Advanced Logging — $600 / year

- **Structured JSON logs:** Every record uses a consistent data shape and known event codes for predictable parsing and querying.
- **Dedicated native event log:** A dedicated NVM for Windows log and event source rather than the generic Windows Application log.
- **SIEM integration:** Feed structured events into existing security information and event management tools for centralized analysis and auditing.

### Governance — $3,000 / year

- **Central policy management:** Deploy ADMX/ADML templates through Active Directory Group Policy or Microsoft Entra using registry-backed settings.
- **IT-managed NVM firewall:** Centrally enforce approved Node.js versions, npm modules, and trusted command-line tools through organizational policy.
- **Advanced proxy support:** Support Integrated Windows Authentication and automatic proxy configuration through WPAD/PAC.
- **Runtime controls:** Enforce approved Node.js and npm runtime settings through centrally managed policies.
- **Private download gateway and mirror:** Control where Node.js runtime downloads originate across the organization.
- **Certificate of Insurance:** An ACORD 25 Certificate of Insurance is available on request.

## Evaluation priorities

### Cybersecurity

- Authenticode-signed builds are provided by all builds.
- IT-managed installation is provided by Certified Builds.
- SLSA provenance, CycloneDX SBOMs, and VEX reports are provided by Trust Artifacts.
- SIEM-integrated logging is provided by Advanced Logging.
- Centralized Node.js and npm policy enforcement is provided by Governance.
- A private Node Mirror is provided by Governance.

### Procurement

- Site-wide licensing, IT-managed installation, Trust Center access, security-pack access, vendor risk controls, and subscription management are provided by Certified Builds.
- SLSA provenance, CycloneDX SBOMs, and VEX reports are provided by Trust Artifacts.
- A Certificate of Insurance is provided by Governance.
- EULA redlining and invoicing are available through a Custom Annual Agreement.

### Compliance

- Authenticode-signed builds are provided by all builds.
- Trust Center access, security-pack access, vendor risk controls, and subscription management are provided by Certified Builds.
- SLSA provenance, CycloneDX SBOMs, and VEX reports are provided by Trust Artifacts.
- SIEM-integrated logging is provided by Advanced Logging.
- Centralized Node.js and npm policy enforcement and a Certificate of Insurance are provided by Governance.
- Named data flows and subprocessors are documented in Author Software's operational assurances.

The interactive [Certified Builds configurator](https://nvm-windows.com/certified) derives a recommended product selection from each persona's priorities. Users can change the cart without losing the selected persona and can restore its recommendation at any time.

## Operational assurances

### Product and data practices

- **No product data collection:** NVM for Windows runs on-premises and does not collect user data.
- **AICPA scope depends on deployment:** NVM for Windows runs locally. Node Mirror customers may optionally store rules on Author Software servers, which may bring that configuration within applicable AICPA service-provider scope.
- **No AI model training:** Author Software does not use customer data to train AI models.

### Business and audit support

- **Stripe payment processing:** Payments are processed through Stripe using PCI-compliant payment infrastructure.
- **US-based company:** Author Software Inc. is based in the United States.
- **Documented subprocessors:** A current list of subprocessors and their locations is freely available in the Trust Center.
- **Auditor portal access:** Customers can grant auditors access to the Customer Portal to review current security and compliance materials.

## Custom Annual Agreements

Custom agreements are available for organizations that need:

- EULA redlining
- Onboarding support
- Invoice-based purchasing and payment terms

Custom agreements are priced by request. Use the contact form on the [Certified Builds page](https://nvm-windows.com/certified) to discuss requirements.

## Security pack and contact

The [Certified Builds page](https://nvm-windows.com/certified) provides a security-pack request form for selecting available documents and adding evaluation notes. A general contact form is also available from the site navigation.

- [Configure and purchase Certified Builds](https://nvm-windows.com/certified)
- [Customer Portal](https://portal.author.io)
- [NVM for Windows documentation](https://docs.nvm-windows.com)
- [Author Software](https://author.io)
