Security approach
Novuslo is designed for private enterprise deployment with explicit identity, credential, execution, and data boundaries. The exact controls available to a customer depend on the software version, deployment architecture, configured integrations, and commercial agreement.
Customer-controlled deployment
Private deployments may operate in a customer-managed VPC, private cloud, or on-premises environment. Customers remain responsible for infrastructure security, network controls, identity providers, connected systems, model providers, backups, and administrative access unless a written agreement states otherwise.
Operational practices
- Use least-privilege access for users and connected services.
- Separate production and non-production environments.
- Protect credentials and rotate them according to organizational policy.
- Review audit and execution records for unexpected activity.
- Require human approval before sensitive or irreversible actions.
- Keep supported software and dependencies current.
Vulnerability reporting
Send a detailed report to security@novuslo.com. Include the affected component, reproduction steps, potential impact, and any supporting evidence. Do not access data that is not yours, disrupt services, use social engineering, or publicly disclose an unresolved issue.
Our response
We will acknowledge good-faith reports, investigate reproducible issues, prioritize remediation according to risk, and coordinate disclosure where appropriate. This page does not create a bug bounty or promise payment.
Certifications
Novuslo does not represent that it holds a security certification unless that certification is expressly identified in a current written statement from Novuslo LLC.