Novuslo
Security overviewReport an issue

TRUST

Security Policy

Responsible reporting and deployment security

Security approach

Novuslo is designed for private enterprise deployment with explicit identity, credential, execution, and data boundaries. The exact controls available to a customer depend on the software version, deployment architecture, configured integrations, and commercial agreement.

Customer-controlled deployment

Private deployments may operate in a customer-managed VPC, private cloud, or on-premises environment. Customers remain responsible for infrastructure security, network controls, identity providers, connected systems, model providers, backups, and administrative access unless a written agreement states otherwise.

Operational practices

  • Use least-privilege access for users and connected services.
  • Separate production and non-production environments.
  • Protect credentials and rotate them according to organizational policy.
  • Review audit and execution records for unexpected activity.
  • Require human approval before sensitive or irreversible actions.
  • Keep supported software and dependencies current.

Vulnerability reporting

Send a detailed report to security@novuslo.com. Include the affected component, reproduction steps, potential impact, and any supporting evidence. Do not access data that is not yours, disrupt services, use social engineering, or publicly disclose an unresolved issue.

Our response

We will acknowledge good-faith reports, investigate reproducible issues, prioritize remediation according to risk, and coordinate disclosure where appropriate. This page does not create a bug bounty or promise payment.

Certifications

Novuslo does not represent that it holds a security certification unless that certification is expressly identified in a current written statement from Novuslo LLC.

© 2026 Novuslo LLC. All rights reserved.
PrivacyTermsAcceptable use