Security

Trusted with the model that runs your business.

Isolation · Encryption · Ownership · Auditability

Your planning model is the most sensitive asset in finance. We treat it that way.

Novi holds the shape of your business: drivers, salaries, scenarios, the logic behind every number. Security isn't a feature bolted on here; it's the foundation the platform is built on. Below is exactly how we protect your data, and an honest account of where we are, with no badges we haven't earned.

A database per client

Never co-mingled

Your data lives in its own dedicated database, never in the same database as another customer's.

Single-tenant option

Physical separation

Need more than logical isolation? Run on your own dedicated, single-tenant infrastructure.

Encrypted

In transit & at rest

Data is encrypted on the wire and on disk, end to end.

Yours, always

Never sold or trained on

Export any time. Your data is never sold and never used to train AI models.

Audited

Every change tracked

Who changed what, and when: logged, attributed and reversible.

GDPR-aligned

European by default

Built for European finance teams, with data protection designed in.

01· Isolation by design
Separation, not a setting

A separate database for every client. No exceptions.

Most multi-tenant software keeps every customer's data in one shared database, separated only by a tenant ID on each row, one query mistake away from a leak. Novi doesn't work that way. Every client gets its own dedicated database. Your data is never stored next to another customer's, not in the same table, not in the same database. Separation is structural, enforced by the boundary itself, not by a filter we have to remember to apply.

Most platforms isolate tenants with a WHERE clause. We isolate them with a database boundary.

Standard for everyone

Logical isolation, by default

Every client runs against its own dedicated database, fully separated from every other tenant, on every plan, with nothing to configure. Cross-tenant access isn't restricted by policy; it simply has no path to exist.

On request

Physical isolation, when you need it

For organisations that require more than logical separation, we offer optional single-tenant environments: your own dedicated infrastructure, shared with no other customer. For when a separate database isn't enough and you need separate everything.

02· Your data is yours
Whose data it is

Your data is yours. We just hold it.

Everything you put into Novi, and everything CLARA comes to understand about how your business models itself, belongs to your organisation, not to us. It is never shared across tenants. It is never sold. And it is never used to train AI models, ours or anyone else's. You can export your model and its full history whenever you like and take it with you. Leaving is a feature, not a fight.

The institutional knowledge that builds up inside your model is yours to keep, and yours to leave with.

When you ask CLARA a question, she reasons over your model, not a shared one, and not a model trained on other customers' data. Your numbers stay inside your boundary.

03· The controls
The fundamentals

The boxes your security team needs to check.

Beyond isolation, the fundamentals, handled the way you'd expect from a platform trusted with financial data.

Encryption in transit

All traffic is protected with modern TLS. Nothing crosses the wire in the clear.

Encryption at rest

Encrypted twice over: at the storage volume and at the database file itself.

Least-privilege access

Access is scoped, authenticated and logged. People and services get only what they need.

Authentication

Token-based authentication, with SSO and MFA available on Enterprise plans.

Audit trail

Every change is tracked, attributed and reversible. The model carries its own history.

Backups & recovery

Regular, encrypted backups. Your work survives a bad day.

Resilient infrastructure

Built on redundant, monitored infrastructure designed to stay up under load.

Secure by construction

Security is part of how we build, reviewed in design and code, not bolted on after.

Data Processing Agreement

A DPA and a current list of sub-processors are available on request.

04· Straight talk on compliance
No badges we haven't earned

We'd rather tell you the truth than sell you a logo.

Most security pages open with a wall of certification badges. We can't do that honestly, not yet. We're a young company, and a SOC 2 or ISO 27001 audit is a serious undertaking we haven't completed, so we won't imply that we have. What we can give you is better than a logo you can't inspect: the real architecture, described plainly, and a straight answer about where we're going. If your procurement process requires a finished audit today, tell us early. We'd rather have that conversation up front than waste your team's time.

True today
  • A dedicated database per client: never co-mingled.
  • Optional single-tenant environments for physical isolation.
  • Encryption in transit and at rest.
  • Full audit trail: every change attributed and reversible.
  • Your data stays yours: never sold, never used to train models.
  • GDPR-aligned processing, with a DPA on request.
On the roadmap
  • SOC 2: planned as we scale; we'll publish the date when it's real.
  • ISO 27001: the direction of travel, not a claim we make today.
  • Independent penetration testing on a regular cadence.
  • A public trust centre with live status and documentation.

We publish certifications when they're earned and verifiable, never as "coming soon" theatre. When a date is real, it goes here.

05· Privacy & residency
Where your data lives

Built for European finance, with privacy by design.

Novi is built for European finance teams, and data protection is designed in rather than retrofitted. We process personal data under the GDPR, offer a Data Processing Agreement, keep a current list of sub-processors, and support data-subject access and deletion requests. Your data is hosted in the European Union, and you choose the region it lives in.

Data residency isn't a paid add-on you negotiate. It's the default you start from.

Trust is earned in specifics, not slogans. Bring us the specifics.

Send us your security questionnaire.

Your IT and security teams will have questions. Send them our way. We answer in detail, in writing, and we don't hand-wave. Ask us about single-tenant deployment, data residency, or anything your review requires.