How we protect customer data, identity, and infrastructure · Last updated: April 20, 2026
Security at Nova AI Ops is engineered into every layer of the platform — how we encrypt your data, how we control who can touch it, how we log every action, and how we respond when something goes wrong. This page is a current, honest snapshot of where our program stands and how to engage with it.
We’re explicit about what we have today versus what’s in flight. If your procurement team needs evidence on any of these, email security@novaaiops.com and we’ll respond within one business day.
Audit underway with a Big-4-affiliated firm. Controls live; observation window in progress. Letter of engagement and bridge letter available on request.
DPA, Standard Contractual Clauses for transfers, documented sub-processors, and a DSAR process. Lawful basis tracked per processing activity.
California consumer privacy rights honored: access, deletion, correction, opt-out of sale (we don’t sell), and limit-use of sensitive information.
Pre-signed DPA available, including SCCs and a list of sub-processors. Email privacy@novaaiops.com to receive the signed PDF.
Customer data is protected end to end. We hold ourselves to controls modeled on the AICPA Trust Services Criteria and ISO 27001 Annex A, even as our SOC 2 audit completes.
All API and UI traffic uses TLS 1.3 with modern cipher suites. HSTS is enforced site-wide. Internal service-to-service traffic is mutually authenticated.
Sensitive data is encrypted with AES-256. Keys are managed by our cloud provider’s KMS using envelope encryption with regular rotation.
Customer workloads run in logically isolated tenants with row-level security on shared data stores. Cross-tenant access is structurally impossible at the application layer.
Automated, encrypted backups with point-in-time restore. Disaster-recovery runbooks exercised on a regular cadence; RPO and RTO targets shared on request.
You decide who in your org can do what. Identity is the front door, so we put real engineering into it.
Single sign-on with Okta, Azure AD, Google Workspace, JumpCloud, and any SAML 2.0 IdP. Available on Pro and Enterprise plans.
Automated user provisioning and deprovisioning. New hires get scoped access on day one; departures lose access automatically.
Granular RBAC with least-privilege defaults. Custom roles and resource-scoped permissions for teams that need fine control.
MFA required for all administrators and available for all users. Supports TOTP authenticator apps and WebAuthn / FIDO2 hardware keys.
Nova AI Ops is an observability platform — we apply the same rigor to our own systems as we ship to customers.
We use a small number of trusted sub-processors to deliver the service. Our full, current list is maintained as part of the DPA — what follows is a summary.
| Sub-processor | Purpose | Region |
|---|---|---|
| Amazon Web Services (AWS) | Primary cloud infrastructure, storage, compute | US, EU |
| Cloudflare | CDN, DDoS protection, WAF, DNS | Global |
| Anthropic | AI model inference for agent and copilot features | US |
| Stripe | Payment processing | US |
| Postmark / SendGrid | Transactional email delivery | US |
We notify customers of material changes to our sub-processor list before they take effect, per our DPA.
If you believe you have found a security vulnerability in Nova AI Ops, we want to hear from you. Email security@novaaiops.com with:
Our commitments to you.
Nova AI Ops maintains a documented security incident response plan covering detection, triage, containment, eradication, recovery, and post-incident review. Customer-impacting incidents are communicated through status.novaaiops.com and to designated security contacts via email. We commit to notifying affected customers without undue delay where required by law or contract.
Our handling of personal data is governed by our Privacy Policy. Highlights:
For all security-related inquiries:
Security questions / questionnaires: security@novaaiops.com
Privacy / DPA / DSAR: privacy@novaaiops.com
Vulnerability reports: security@novaaiops.com
System status: status.novaaiops.com
Nova AI Ops · AI-native SRE & observability platform