Governance Overview
How NovaceneAI® Safeguards the Privacy and Security of Customer Data
Security, Privacy & Governance at a Glance
The NovaceneAI Platform is designed to operate within rigorous governance, compliance, and oversight frameworks. Engineered for regulated environments from the ground up, it combines third-party audited data privacy controls, flexible deployment options, robust access controls, and comprehensive AI governance. Together, these capabilities ensure that the platform not only accelerates AI adoption but also meets the requirements of security‑sensitive, highly regulated, and mission‑critical environments.

Compliance & Certifications
The NovaceneAI Platform is SOC 2 Type II compliant. The platform and the company’s practices are regularly monitored and independently audited to confirm that its systems and processes meet strict criteria for data security, availability, and confidentiality. This independent audit validates that controls are well-designed and consistently enforced to securely manage customer data, mitigate risk, and protect sensitive information. Compliance attestation is available upon request.

Data Privacy & Security
Data Ownership
Customers retain ownership of their data and any outputs derived from it. Processing is limited to delivering contracted services under agreed terms and controls. Customer data is not used or disclosed for any other purpose, including secondary or unrelated processing.
Data Encryption
Customer data is encrypted in transit (TLS 1.2–1.3) and at rest (AES‑256 or stronger). Keys and cryptographic materials are managed under documented controls with restricted access. These encryption controls are subject to independent audit and ongoing verification.
Backup & Disaster Recovery
Backups are centrally orchestrated with defined cadence and retention, and stored redundantly within the selected region across independent fault domains. This ensures recoverability through restorations in accordance with RTO and RPO objectives.

Deployment & Hosting Models
The NovaceneAI Platform supports flexible hosting options. The platform can be deployed on premises or within a customer managed cloud environment. The platform is fully containerized, which makes it deployable onto any cloud and interoperable across multiple clouds.
On-Prem & Customer-Managed Cloud
On premises and customer managed cloud deployments ensure the NovaceneAI Platform is installed within the customer’s cloud account and governed by internal IT policies. Data and workloads remain within the customer’s environment under existing security and compliance controls.
Single Tenant Hosting
A dedicated, single tenant, private environment in which customer data is isolated from other customers’ data. Available with leading cloud service providers (CSPs)—including Azure, AWS, GCP, and Oracle Cloud—this model offers privacy advantages over multi tenant SaaS products.
Air-Gapped / Offline
Available for customers that require complete, continuous isolation from the public internet. Operates with no external connectivity and uses controlled, auditable processes for software updates and data transfer, with change‑control procedures enforced to maintain isolation.





Access Control & Auditability
The NovaceneAI Platform enforces granular role and group based access controls that restrict data visibility and permitted operations for authenticated users, supporting separation of duties and least privilege assignment. Administrative and user activity is logged with user, action, and timestamp for authorized review. Together, these controls enable secure distribution of data, insights, and permissions and provide continuous operational oversight.

AI Governance
Organizations gain full transparency into how data is processed, how models make decisions, and how outputs are generated — ensuring every AI insight is explainable, auditable, and aligned with business context.
AI Provider Choice
The NovaceneAI Platform supports commercial generative AI providers (e.g., OpenAI, Anthropic, Google), in cloud models (e.g., Azure OpenAI, AWS Bedrock, Google Gemini), and on disk models, including open source SLMs and LLMs. Configurations prevent data retention and model training on customer data, while local options operate without external transmission to enhance privacy and cost control.1
AI Explainability
The NovaceneAI Platform provides teams with the ability to review human-readable rationales for every AI output produced, supporting trusted AI within regulated operational environments. These rationales provide justifications that help teams understand, trust, and improve AI outcomes on an ongoing basis. The rationales are easily accessible through the platform’s built-in insight visualization dashboards.
AI Observability & Traceability
With NovaceneAI Traces™, teams are able to visualize data lineage as it traverses through AI workflows, supporting auditability and continuous improvement. The platform provides visibility into AI orchestration decisions, agent selection, parameters, input context, insights produced, and AI rationales. Every AI output includes a link to its trace, providing easy access to see how each insight was produced.
AI Guardrails
The platform supports governance of outcomes through policy based business guardrails, including standard operating procedures, playbooks, and contextual policies. This enables organizations to achieve tailored AI outcomes that align with business processes and domain ontologies and provide actionable insights appropriate to operating conditions.
Human-in-the-Loop
The platform provides a built-in capability for business experts to provide structured feedback to the AI directly rather than relying on intermediary teams. This feedback produces auditable updates to AI instructions prior to deployment and allows experts to rate AI accuracy and quality to ensure accountability and continuous improvement.
Ethical AI
Ethical AI practices are applied across planning, design, and implementation to support responsible use in regulated environments. These practices include policy alignment, risk and impact assessment, bias and safety evaluation, documentation and transparency of model behavior, and human in the loop oversight with clear accountability.


1 Performance and cost may vary between LLM options, including between similar services like OpenAI and Azure OpenAI. On-disk models may require additional compute resources.

Data Sovereignty
International customers wishing to access the NovaceneAI Platform through a hosted SaaS model are able to do so through CSPs, datacenters and regions of their choice. NovaceneAI supports both data residency and data sovereignty, enabling organizations to store and process data within specific geographic jurisdictions. This ensures compliance with local regulations and guarantees that sensitive information remains under the legal protection of the selected country, enabling organizations to meet strict regional data governance requirements.


