Skip to content

Docs / 12 of 14

Security model

Tenancy, encryption, data classes, deployment paths, audit logs, and the dated compliance roadmap. Written for a workspace admin filling a questionnaire.

4 min read

This page is the admin short form of /security and /trust. Pasteable facts, not a pitch. We do not claim certifications we do not hold.

The public Trust page is in global nav, not buried in the footer. Product pages carry their own data-handling block: what is read, where it is processed, retention, whether a human can see it, and that customer data is not used to train models.

Tenant boundary

The tenant is the Organization. A User is global. Access is a Membership.

Three data zones:

  1. Public catalog — Product, Category, Collection, Integration, Plan. No orgId.
  2. Tenant data — Membership, Invitation, ApiKey, Cart, Order, Purchase, Subscription, Invoice, Entitlement, UsageEvent, AuditLog. Every row is scoped to the Organization.
  3. Platform data — webhooks, leads, waitlist. Staff only.

orgId is never taken from the client body. It comes from the session's active Organization, the ApiKey, or an orgSlug that is checked against Memberships. A slug that is not yours returns 404, not 403.

Defense in depth: request context, tenant-scoped database client, and row-level security in Postgres. Staff isStaff grants /admin. It does not grant Organization data.

Data classes

ClassWhat it isOn our infra
account_dataWork email, hashed password or IdP subject, billing email, company name, tierYes
workspace_configMappings, schedules, approval matrices, templates you typed into a hosted toolYes
connector_secretsOAuth refresh tokens, pasted API keys, BYOK materialYes, envelope-encrypted
run_payloadInput document, prompt context, output of one runYes, unless zero-retention or self-hosted
run_metadataRun id, slug, timestamps, status, credits, payload hash, actorYes (including under zero-retention)
audit_eventWho, what, when, IP, object idYes

We do not keep a second AR/AP subledger. Your GL, CRM, HRIS, mailbox, and bank remain the system of record. Payment cards are never stored; once checkout takes payment, Stripe processes cards as our payment processor.

Deployment and data flow

deploymentWhat leaves / what stays
hostedYou type or upload into nox.markets. Processing is on our side. Retention is the product page.
connectedWe hold scoped tokens. We read and write the objects the product page names. Processing is in memory for the run; retention is the stated window. Revoke the grant and it cannot act.
self-hostedYou run it. License check / heartbeat may reach us. Documents, tokens, and prompts do not have to.

Some hosted and connected products send prompts and retrieved context to a named model subprocessor. We do not claim customer data “never goes to a model.” The subprocessor list is public (/legal/subprocessors). If a vendor is not on that list, we are not allowed to use them on your data.

Deterministic steps (post a draft that already has a GL code, send a template email) do not call a model.

Customer data is not used to train nox.markets models or, by contract, provider foundation models. We use no-training / zero-data-retention terms with model vendors where the endpoint offers them. If an endpoint cannot be put on those terms, we do not route customer data to it.

Encryption and residency

TLS in transit (TLS 1.2 minimum, TLS 1.3 preferred). AES-256 at rest on disks. Connector secrets get a second envelope layer so a database dump is not a token dump.

  • Every tier: a Hetzner data center in Nuremberg, Germany. No other processing region is offered.

Customer-managed keys: Not yet available. Planned for enterprise, target 2027-06-30. Until then, we manage the keys.

Identity and audit

Google and Microsoft OAuth on starter. Password accounts require MFA. SAML (growth+) and SCIM (scale+) are Not yet available in this build; designed behavior is on /security.

Audit: authentication, role changes, invites, integration connect/revoke, product pause, runs, exports, plan changes. We log that a run happened and a hash. We do not copy run_payload into the audit table.

Retention of audit rows: 30 days starter, 12 months growth, 36 months scale. Export from the dashboard is growth+. SIEM stream: scale+, Not yet available.

Staff have no standing production access to run_payload. Break-glass is ticketed, time-boxed, logged.

Off switch, export, deletion

Pause the product. Revoke OAuth. Export configuration and output history in open formats (dashboard export: Building the export. Large logs take a minute. / Export started. We will email {email} when the file is ready.).

Work already in QuickBooks, HubSpot, or a mailbox stays there. Cancellation does not unwind it.

Organization delete: owner confirms the slug. Soft-delete immediately; hard-purge of tenant rows after 30 days. UsageEvent retention is 90 days. AuditLog 400 days. Legal hold on enterprise can pause deletion for named objects.

self-hosted licences include a source-escrow clause.

Compliance roadmap (not held)

Status as of 2026-09-15. Planned is not a report.

FrameworkStatusTarget
SOC 2 Type IPlanned2027-05-31
SOC 2 Type IIPlanned (observation 2027-06-01 → 2027-11-30)2027-12-15
ISO/IEC 27001Planned2028-09-30
CCPA / CPRAOperational as law, not a certificationLaunch
HIPAA / BAANot offered until BAA is live. ePHI forbidden until then2027-06-30, enterprise only
Independent pen testPlanned (first test)2026-12-15

growth may receive the SOC 2 Type II report when issued, under NDA. Until then the public sentence is Planned plus the date above.

There is no such thing as “HIPAA certified.” Do not put ePHI in run_payload until a BAA exists.

DPA: Request our DPA on /security. Custom paper is a scale / enterprise conversation.

Finance-specific controls

finance-backoffice products default to human approval. Extracted fields cite the source document. Each listing names a failure mode; a published eval with an error rate is planned and not present. Anyone claiming hallucination is solved is not describing this product line.

Next