NEW The NOVA engine now understands Saudi dialects with higher accuracy
Legal · Information security

Security Statement

This statement records our commitments to protecting the platform and our customers' data: encryption, access governance, incident response, responsible disclosure: and your share of the responsibility. We wrote it in the register of commitments, so procurement reviews can quote it as-is.

Last updated: June 2026

This is a policy statement issued by NOVA, a Saudi company headquartered in Riyadh. It applies to the NOVA platform and its managed services, and complements the Terms of Service, the Privacy Policy, and the data processing agreement where one is signed.

To avoid duplication: this page states what we commit to. How the controls work inside the platform: protocols, algorithms, the controls table: is documented on the Security page in the Trust Center, the technical companion to this statement.

1

Encryption in transit & at rest

We commit to encrypting customer data on every path it takes through our managed services:

  • In transit: every connection between the browser and the platform, and between connectors and linked systems, runs over encrypted channels.
  • At rest: data stored on NOVA Cloud is encrypted at the storage layer.
  • Key management: in private-cloud (VPC) and on-premises deployments, encryption keys remain owned and managed by you.

The technical standards currently in force are documented on the Security page; we commit to keeping them aligned with recognized good practice: without lowering the level of protection.

2 · Access governance

Access at least privilege

Our team's access to production systems and customer data follows one rule: the minimum required for the task, and no more.

  • Permissions are granted by role, scoped to operational need, and reviewed periodically.
  • Access to customer data is restricted to a documented operational need: such as support at your request: and recorded in our internal logs.
  • When a role changes or an employment relationship ends, access is revoked without delay.
  • Development environments are isolated from production, and customer data is not used for development or testing.
3

Security incident response

We operate a documented internal process for security incidents: impact assessment, containment, remediation, and a lessons-learned review.

  • If a security incident affects your data, we notify you without undue delay with the information available to us: the nature of the incident, the data affected as far as known, and the actions we have taken.
  • We keep you updated as remediation progresses through to closure, and provide a post-incident summary on request.
  • This commitment is designed to support your own legal obligations: including notification duties under the Saudi Personal Data Protection Law (PDPL) where they apply.

This statement does not publish contractual response times; where specific service levels are agreed, your enterprise agreement is the authoritative reference.

4

Responsible disclosure

We welcome reports from security researchers and treat them seriously.

  • Channel: email [email protected] with the vulnerability details and reproduction steps.
  • We confirm receipt and keep you informed through to closure.
  • Good-faith research within the responsible-disclosure rules will face no action from us.

The full rules: the window before public disclosure and the boundaries of research: are published on the Security page.

5

Infrastructure providers

We use infrastructure providers to operate NOVA Cloud inside the Kingdom. Our stance on them is fixed:

  • Every provider is contractually bound to a level of protection no lower than what we commit to in this statement.
  • No provider processes customer data beyond what is needed to run the service: and we never sell data or trade it for advertising.
  • Customers with a signed data processing agreement are notified of any material change to this approach under the terms of that agreement.
  • In private-cloud (VPC) and on-premises deployments, your flow content never passes through our infrastructure or our providers at all.
6

Your responsibilities: the shared model

Security is a shared responsibility: we secure the platform, its infrastructure, and our operations: you secure your account and what you connect to it. You are responsible for:

  • Keeping credentials confidential, and managing users and their permissions inside your account.
  • Scoping flow and agent permissions to the sensitivity of your data: the platform executes what your permissions allow.
  • The lawfulness of the data and systems you connect, and obtaining the consents their owners require.
  • Notifying us immediately if you suspect unauthorized access to your account.
7

Contact & changes to this statement

For questions about this statement, write to [email protected] or contact us. Security review teams will find the technical detail in the Trust Center, and our approach to regulatory expectations in the Compliance Statement.

If we make a material change to this statement, we notify customers before it takes effect: and we do not weaken the level of protection documented here during your subscription without prior notice.