Security
Our security posture
How Noverionex LLC handles subprocessors, data, authentication, and encryption for Noverionex CRM and Warden. Request an executed DPA at hello@noverionex.com.
Subprocessors
From the Subprocessor List (Annex B to the DPA), last updated July 27, 2026. Material changes are notified as described in the DPA.
| Subprocessor | Purpose |
|---|---|
| Vercel Inc. | Application hosting, serverless functions, edge delivery |
| Supabase (managed PostgreSQL) | Primary application database |
| Stripe, Inc. | Payment processing and subscription management |
| Google LLC | OAuth sign-in; optional workspace Gmail integration |
| Resend, Inc. | Transactional email delivery |
| OpenAI, LLC | AI analysis features (Smart Metrics, Zara, triage assistance, where enabled) |
| Cloudflare, Inc. | CDN, DNS, and security blocking integrations (Warden, where configured) |
| Vercel Blob | File storage for Brand Kit and uploaded assets |
| Twilio Inc. | SMS / telephony (where configured) |
| ProxyCheck, AbuseIPDB, VirusTotal (where configured) | Warden IP reputation / threat intelligence enrichment |
Customer-configured integrations (SMTP, custom webhooks, client sites monitored by Warden) are not Noverionex LLC subprocessors unless Noverionex has a direct agreement with them for your account.
Data handling and retention
From the Data Processing Addendum (template v1.1, July 27, 2026).
Noverionex LLC processes Customer Personal Data as a processor (or CCPA service provider) to deliver Noverionex CRM, Warden, and related services — hosting, storage, retrieval, analysis, transmission, security monitoring, reporting, AI-assisted features where enabled, backup, and support.
Upon termination or expiry of Services, you may export Customer Personal Data using available tools for thirty (30) days (or longer if agreed).
After the export window, Noverionex shall delete or anonymize Customer Personal Data in active systems within ninety (90) days, except where retention is required by law or in encrypted backups on normal rotation schedules.
Security incidents affecting Customer Personal Data are notified without undue delay and in any event within seventy-two (72) hours after confirmation.
Full DPA template: request execution at hello@noverionex.com. Related policies: Privacy, Data Deletion.
Authentication
Sign-in uses NextAuth with Google OAuth. Workspace access is also gated by license keys issued for Noverionex CRM and Warden subscriptions.
Encryption
Data is encrypted in transit using TLS 1.2+. The primary Postgres database is hosted on Supabase, where all data at rest — tables, indexes, write-ahead logs, and backups — is encrypted with AES-256 by the underlying cloud infrastructure. This is always enabled and cannot be disabled. See Supabase's security documentation for their full attestation.
SOC 2
Noverionex LLC is not currently SOC 2 certified.
We're a small company and a SOC 2 audit is ahead of us, not behind us. If SOC 2 attestation is a hard requirement for your clients, we're not the right fit yet — and we'd rather say that here than after you've onboarded.