Back to Nova AI Ops
TRUST CENTER · SECURITY & COMPLIANCE

Trust, earned in writing.

Everything your security and procurement teams need to vet Nova AI Ops, our compliance posture, sub-processors, system status, and how to request the artifacts (DPA, MSA, security questionnaire, SOC 2 progress letter, pen test summary) on file.

Compliance & certifications

In progress

SOC 2 Type II

Audit underway. Controls in place; observation window in progress. Bridge letter and progress summary available on request.

Live

GDPR (EU/UK)

Data Processing Agreement, Standard Contractual Clauses for international transfers, documented sub-processors, and a DSAR process.

Live

CCPA / CPRA

California consumer privacy rights honored, access, deletion, correction, opt-out of sale (we don't sell), and limit-use of sensitive information.

Live

Data Processing Agreement

Pre-signed DPA available, includes SCCs and the sub-processor list. Use the form below or email privacy@novaaiops.com.

Aligned

HIPAA (US Healthcare)

Architecture supports HIPAA-aligned deployments with BAAs available for healthcare customers. PHI never leaves your tenant boundary; details on request.

Planned

ISO 27001

Planned to follow the SOC 2 Type II report. Many ISO 27001 controls overlap; we'll start the gap analysis after the SOC 2 observation window closes.

System status

All systems operational
Live status, incident history, and uptime metrics at status.novaaiops.com

Request a document

Available on request: SOC 2 Type II progress letter, DPA, MSA, security questionnaire (CAIQ / SIG-Lite), pen test summary, and the full sub-processor list. We respond within one business day.

Hold Cmd/Ctrl to select multiple.

Request received

Thank you. Our security team will review your request and respond within one business day. For urgent procurement timelines, email security@novaaiops.com with the deadline.

Sub-processors

A short list of trusted third parties we use to deliver Nova AI Ops. The complete and current list ships with the DPA.

Sub-processor Purpose Region
Amazon Web Services (AWS) Primary cloud infrastructure, storage, compute US, EU
Cloudflare CDN, DDoS protection, WAF, DNS Global
Anthropic AI model inference for agent and copilot features US
Stripe Payment processing US
Postmark / SendGrid Transactional email delivery US

Related

Security narrative →
Encryption, identity, access control, audit logging, and our vulnerability-disclosure program.
Privacy policy →
What we collect, why, how long we retain it, and how to exercise your rights.
Terms of service →
The contract that governs your use of Nova AI Ops, plain language with a link to the legal text.

Direct contacts

Security & vulnerability
security@novaaiops.com
Reports, questionnaires, SOC 2 inquiries
Privacy & data protection
privacy@novaaiops.com
DPA, DSAR, GDPR / CCPA inquiries