Trust Center
What auditors, DPOs and CISOs want to know before the pilot.
Security policies, compliance mappings and architecture documentation for Nova IAM: 13 public documents, readable without an NDA or sign-up.
Start by role
Who you are and where to start
-
For Auditors
Compliance evidence
-
For DPOs
GDPR & Data Protection
-
For CISOs
Security Architecture
-
For Engineering
Deployment & Operations
Status today
Current compliance status
Each item below shows whether it is done, in progress or planned.
| Topic | Details | Status |
|---|---|---|
| Regulations | ||
| GDPR / DSGVO | Article mapping for controllers | Mapping documented |
| NIS-2 / NIS2UmsuCG | In force since 6 December 2025 · Sec. 30 BSIG risk management · Sec. 32 BSIG reporting · IAM mapping | Documented |
| Cyber Resilience Act (CRA) | Reporting obligations under Art. 14 apply since 11 September 2026 · further obligations from 11 December 2027 · Vulnerability management · SBOM | In progress |
| Controls and processes | ||
| Audit log | Log of who, when and from where · Schema versioned | Implemented |
| Access Control (RBAC) | Role model · Inheritance · Provisioning control | Documented |
| Vulnerability Disclosure | Public policy · Safe harbour · Acknowledgement within 2 business days | Active |
| Certifications and testing | ||
| ISO/IEC 27001 | No certificate. We will announce the date of the certification audit once a certification body has been engaged. | No date yet |
| SOC 2 Type 1 | No SOC 2 report. Planned after ISO 27001, no fixed date (see roadmap). | After ISO 27001 |
| External penetration test | We will announce the date once it is contractually fixed · results under NDA with pilot customers | Date to follow |
Maturity: We do not hold any certifications yet. What we can demonstrate today is set out in 13 public documents; open items are listed in the status above.
Compliance mappings
Regulatory coverage
Which regulations our documents relate to, with the status from the overview above. A reference does not replace a certificate or an audit report.
-
Mapping documented
GDPR / DSGVO
Relevant documents
- GDPR Compliance
- Data Protection
- Incident Response
-
Documented
NIS-2 / NIS2UmsuCG
Relevant documents
- NIS-2 Compliance
- Access Control
- Audit Trail
- Incident Response
-
In progress
Cyber Resilience Act (CRA)
Relevant documents
- Cyber Resilience Act
- Security Policy
- Vulnerability Disclosure
- Change Management
Other frameworks
| Regulation | Relevant documents | Status |
|---|---|---|
| ISO/IEC 27001 | Security Policy · Architecture Security · Access Control · Change ManagementWhat the documents relate to, not a certificate | No date yet |
| SOC 2 | Security Policy · Audit Trail · Access Control · Change ManagementWhat the documents relate to, not a SOC 2 report | After ISO 27001 |
Documents
Policies and compliance documents
13 public documents: policies, compliance mappings and architecture. Click to read or download as Markdown source.
Security policies
6 documents
| Document | Contents | Tags |
|---|---|---|
| Security Policy | Security controls, authentication, data protection, audit logging. | CISOSecurity |
| Data Protection Policy | Data categories, processing principles, third-party sharing, breach notification procedures. | DPOLegal |
| Access Control Policy | RBAC model, inheritance rules, provisioning controls, account lifecycle management. | SecurityAuditor |
| Change Management Policy | Change categories, review process, deployment standards, migration security. | EngineeringAuditor |
| Vulnerability Disclosure Policy | Reporting process, timelines, safe harbor, credit for researchers. | SecurityPublic |
| Incident Response Plan | Detection, containment, eradication, recovery, communication procedures. | CISOOperations |
Compliance mappings
3 documents
| Document | Contents | Tags |
|---|---|---|
| GDPR Compliance | Article-by-article GDPR mapping, DPA framework, international data transfers. | DPOEU |
| NIS-2 Compliance Mapping | Mapping to NIS-2 Articles 21 and 23 and Sections 30 and 32 BSIG, IAM as NIS-2 control instrument, evidence for authorities and auditors. | CISOEUNIS-2 |
| Cyber Resilience Act | CRA classification, Annex I requirements, vulnerability management, SBOM, ENISA reporting and CE conformity timeline. | CISOEUCRA |
Architecture and operations
4 documents
| Document | Contents | Tags |
|---|---|---|
| Architecture Security Overview | System architecture, security boundaries, data flows and controls matrix. For technical evaluators and pen testers. | CISOAuditor |
| Audit Trail Documentation | Audit log schema, event categories, integrity and limits, regulatory mapping. | AuditorCompliance |
| Deployment Security Guide | Production hardening, TLS setup, network security, monitoring. | DevOpsEngineering |
| SLA Template | Support response times; availability, backup/recovery and service credits only for the planned hosted variant. | SalesLegal |
Complete compliance pack
All documents as ZIP bundle, for audit preparation, RFP responses or internal due diligence.
Security and privacy
Contact
Security reports
security@nova-iam.com
- 2business days to acknowledgement
- 5business days to initial assessment
Safe harbour under our Vulnerability Disclosure Policy. Machine-readable contact details: /.well-known/security.txt
Privacy
privacy@nova-iam.com
Data subject access, rectification, deletion and complaint requests.
Trust & Compliance
trust@nova-iam.com
Compliance pack requests, audit evidence, architecture walkthrough for evaluators.
Next step
Ask your questions live on the system.
30 minutes via video call on the demo system: you name your use cases, we show the relevant functions.
Request a demoWhat happens next
- ReplyWe usually get back to you on the same working day and agree a date with you.
- PreparationWe prepare the demo around the topics you name.
- 30 minutes via video callLive on the demo system with fictitious data: you ask, we show the relevant views.