Logical isolation, by default
Every client runs against its own dedicated database, fully separated from every other tenant, on every plan, with nothing to configure. Cross-tenant access isn't restricted by policy; it simply has no path to exist.
Your planning model is the most sensitive asset in finance. We treat it that way.
Novi holds the shape of your business: drivers, salaries, scenarios, the logic behind every number. Security isn't a feature bolted on here; it's the foundation the platform is built on. Below is exactly how we protect your data, and an honest account of where we are, with no badges we haven't earned.
Your data lives in its own dedicated database, never in the same database as another customer's.
Need more than logical isolation? Run on your own dedicated, single-tenant infrastructure.
Data is encrypted on the wire and on disk, end to end.
Export any time. Your data is never sold and never used to train AI models.
Who changed what, and when: logged, attributed and reversible.
Built for European finance teams, with data protection designed in.
Most multi-tenant software keeps every customer's data in one shared database, separated only by a tenant ID on each row, one query mistake away from a leak. Novi doesn't work that way. Every client gets its own dedicated database. Your data is never stored next to another customer's, not in the same table, not in the same database. Separation is structural, enforced by the boundary itself, not by a filter we have to remember to apply.
Most platforms isolate tenants with a WHERE clause. We isolate them with a database boundary.
Every client runs against its own dedicated database, fully separated from every other tenant, on every plan, with nothing to configure. Cross-tenant access isn't restricted by policy; it simply has no path to exist.
For organisations that require more than logical separation, we offer optional single-tenant environments: your own dedicated infrastructure, shared with no other customer. For when a separate database isn't enough and you need separate everything.
Everything you put into Novi, and everything CLARA comes to understand about how your business models itself, belongs to your organisation, not to us. It is never shared across tenants. It is never sold. And it is never used to train AI models, ours or anyone else's. You can export your model and its full history whenever you like and take it with you. Leaving is a feature, not a fight.
The institutional knowledge that builds up inside your model is yours to keep, and yours to leave with.
When you ask CLARA a question, she reasons over your model, not a shared one, and not a model trained on other customers' data. Your numbers stay inside your boundary.
Beyond isolation, the fundamentals, handled the way you'd expect from a platform trusted with financial data.
All traffic is protected with modern TLS. Nothing crosses the wire in the clear.
Encrypted twice over: at the storage volume and at the database file itself.
Access is scoped, authenticated and logged. People and services get only what they need.
Token-based authentication, with SSO and MFA available on Enterprise plans.
Every change is tracked, attributed and reversible. The model carries its own history.
Regular, encrypted backups. Your work survives a bad day.
Built on redundant, monitored infrastructure designed to stay up under load.
Security is part of how we build, reviewed in design and code, not bolted on after.
A DPA and a current list of sub-processors are available on request.
Most security pages open with a wall of certification badges. We can't do that honestly, not yet. We're a young company, and a SOC 2 or ISO 27001 audit is a serious undertaking we haven't completed, so we won't imply that we have. What we can give you is better than a logo you can't inspect: the real architecture, described plainly, and a straight answer about where we're going. If your procurement process requires a finished audit today, tell us early. We'd rather have that conversation up front than waste your team's time.
We publish certifications when they're earned and verifiable, never as "coming soon" theatre. When a date is real, it goes here.
Novi is built for European finance teams, and data protection is designed in rather than retrofitted. We process personal data under the GDPR, offer a Data Processing Agreement, keep a current list of sub-processors, and support data-subject access and deletion requests. Your data is hosted in the European Union, and you choose the region it lives in.
Data residency isn't a paid add-on you negotiate. It's the default you start from.
Trust is earned in specifics, not slogans. Bring us the specifics.
Your IT and security teams will have questions. Send them our way. We answer in detail, in writing, and we don't hand-wave. Ask us about single-tenant deployment, data residency, or anything your review requires.