Security
Built for regulated banking
Banks need to know where their data lives, who can reach it and how every automated decision can be explained to a regulator. This page sets out how Nova AI platforms are deployed and protected. Our products are designed to support your compliance obligations; they do not certify your institution against any standard.
Table of Contents
Deployment and data residency
Each platform runs where your data already lives, so data can stay in your country and under your control. On-premise options give full data residency control.
- Sentri: deployed in your cloud account and region, and run in shadow mode on live traffic before any decision reaches a customer.
- TraceAI: deployed in your own cloud account or on-premise in your data centre; investigation data stays inside your environment.
- QSafe: SaaS, self-hosted with Docker or Helm, hybrid, or fully air-gapped for the most sensitive networks.
- Agentic AI platform: your choice of cloud region, or on-premise deployment.
Data protection and access
Controls that apply across our platforms and delivery:
- Encryption of data in transit and at rest.
- Role-based access control with fine-grained permissions for agents, data and configuration.
- Single sign-on with SAML 2.0 and OIDC, and multi-factor authentication for all accounts.
- Data residency and retention controls agreed with your team for each deployment.
Audit logging and explainability
Agent actions, user activity and system events are logged, retained according to your policies, and can be exported to your SIEM. Automated decisions come with their reasons: Sentri gives a plain-English explanation for every fraud decision, and TraceAI maps each investigation to MITRE ATT&CK with an evidence timeline.
AI safeguards
Our platforms include guardrails against prompt injection, data leakage and model manipulation. Agents operate within defined boundaries, with escalation to a person for edge cases, and we monitor for anomalous behaviour. Our wider approach is set out in our Responsible AI statement.
Compliance alignment
Our platform and delivery processes are designed to align with ISO 27001 and PCI DSS controls, and with central bank requirements such as those from the Central Bank of Jordan, the Central Bank of Iraq and SAMA. We work with your compliance team to document how a deployment meets your specific obligations. Nova AI does not claim certifications it does not hold.
Security testing
We run third-party penetration testing and vulnerability assessments, alongside continuous automated security scanning. Penetration test reports are available to enterprise customers on request.
Reporting a vulnerability
If you believe you have found a security issue in a Nova AI website or product, email us with the details and steps to reproduce it. Please give us reasonable time to fix it before any public disclosure. Our contact details are also published at nova-ai.ai/.well-known/security.txt.
Security questions
For security questionnaires, due diligence or to report a vulnerability, contact us: