Nova Analytics International
05Security & Compliance

Built for the platforms enterprises depend on.

Nova Analytics designs, operates and hands over systems that meet the security expectations of governments, healthcare networks and financial institutions.

This page is maintained by Nova Analytics International to answer common security and privacy questions about how we build and operate client platforms. It describes our current engineering practices and contractual posture — it is not a third-party certification. Specific controls, retention windows and subprocessors are confirmed in writing per engagement.
01Security pillars

Defence in depth, by default.

Data protection

Encryption in transit (TLS 1.2+) and at rest for managed databases. Least-privilege access and per-environment isolation.

Identity & access

SSO and role-based access controls on internal tooling. Secrets stored in a managed vault — never in source.

Observability

Structured application logs, request tracing and uptime monitoring on platforms we operate for clients.

Resilient infrastructure

Cloud-native architectures on AWS, Azure and GCP with backup, recovery and configurable data residency.

Incident response

Documented runbooks, named owners and customer notification timelines defined per engagement.

Personnel & training

Background-checked engineers, annual security training and signed confidentiality agreements.

02Engineering practices

Data minimization

We collect only what's required to deliver agreed outcomes.

Network segmentation

Production isolated from staging and developer environments.

Change management

Code reviews, signed commits and audited deployments.

Audit-ready logging

Tamper-resistant logs retained per client policy.

03Compliance posture

Procurement-ready, audit-friendly.

Our delivery patterns are aligned with widely recognized control frameworks. For regulated workloads we work with your compliance team to map controls, evidence and reporting to your specific obligations.

Where independent attestations are required, we participate in your auditor's evidence collection and provide artefacts under NDA.

  • ISO 27001-aligned controls
  • GDPR-aligned data handling
  • Configurable data residency
  • Customer-owned encryption keys (on request)
  • DPIA support for regulated workloads
  • Subprocessors disclosed in contract
04Shared responsibility

Nova

Secure-by-default engineering, dependency hygiene, infrastructure-as-code, deployment pipelines, runbooks and operations on platforms we host.

Cloud provider

Physical security, hypervisor isolation, regional availability and the foundational controls documented by AWS, Azure or GCP.

Customer

User provisioning, data classification, acceptable use, business continuity policy and regulatory reporting specific to your jurisdiction.

Security contact

Need our security questionnaire?

Email admin@novaanalytic.ai with your RFP, vendor onboarding pack or DPA template. We typically reply within one business day.

Contact procurement