Loading
Loading
Security is engineered into every layer of the product lifecycle, infrastructure stack, and operational workflow. This page describes the company's public security posture without disclosing sensitive configurations.
AES-256 at rest, TLS 1.3 in transit, and customer-managed key support for regulated workloads. All secrets use hardware-backed key stores.
Mandatory phishing-resistant MFA, role-based access control with attribute-level policies, just-in-time privilege elevation, and quarterly access reviews.
Zero-trust network architecture with micro-segmented workloads, private VPCs, strict egress filtering, and inter-service mTLS.
Threat modelling at design stage, SAST and DAST in CI/CD, software bill of materials for every release, and mandatory peer-reviewed security gates.
Documented IR plan with named roles, escalation paths, and communication templates. On-call rotation with 24/7 coverage and defined severity classifications.
SIEM aggregation with correlation rules, anomaly detection, and automated alert triage. Centralised logging from all infrastructure, application, and security layers.
Automated isolation workflows for compromised assets. Forensic imaging procedures and root-cause analysis protocols. Post-incident evidence preservation chain.
Validated restore procedures from immutable backups. Mandatory post-incident review within 5 business days. Findings tracked to remediation via the risk register.
| Framework | Status | Scope |
|---|---|---|
| ISO/IEC 27001:2022 | Targeting certification | Information security management system |
| GDPR | Operational compliance | Personal data processing |
| NIS2 Directive | Alignment in progress | Network and information systems |
| CIS Critical Security Controls | Implementation group 2 | Infrastructure and operations |
| SOC 2 Type II | On roadmap for growth stage | Trust services criteria |
| EU AI Act | Monitoring and readiness | AI system classification and obligations |
| Cloud Security Alliance CCM | Control mapping in progress | Cloud control matrix |
| OWASP ASVS | Level 2 target | Application security verification |
NOVACORE AI does not claim certifications it has not completed. Certification scope and targets are published only when formal assessment is scheduled, following the principle: 'Designed with a target of…' rather than 'Certified as…'. All control implementations are independently verifiable through audit upon execution of a mutual non-disclosure agreement.
If you believe you have discovered a security vulnerability in any NOVACORE AI system, please contact security@novacore.ai. We commit to acknowledging reports within 48 hours and providing a substantive response within 5 business days. We do not pursue legal action against researchers acting in good faith under our coordinated vulnerability disclosure policy.
Secure AI and high-performance computing for enterprises, governments and research.