TRUST CENTER

Security starts with our own architecture.

Tenant isolation

Portal data is exposed only through scoped server-side RPCs. Underlying Supabase tables are RLS-enabled and not directly readable with public credentials.

Safe red teaming

Active scans require target authorization. The scanner blocks loopback, private, link-local and cloud metadata destinations to reduce SSRF risk.

Runtime hardening

The NovGuard container runs non-root, read-only, no-new-privileges, with all Linux capabilities dropped.

SOC 2 / ISO 27001 mappings are product controls and readiness targets; NovGuard does not claim certification until independently completed.