Trust
Security and trust
Technical controls, independent tests and clear company details. This page describes how NovaMX runs, not a compliance certificate.
Company
Who you are dealing with
NovaMX B.V. is a Dutch company. You can verify our registration details below and reach us through the published contact channels.
- NovaMX B.V., Salland 1, 1948 RE Beverwijk, The Netherlands
- KvK 42107118 · VAT NL869765097B01
- Phone +31 85 130 0982 · contact@novamx.eu
- IBAN NL97 SWNB 3778 2674 95 · BIC SWNBNL22
Independent tests
Public scores for novamx.eu
These reports are for our own website and mail infrastructure. In My NovaMX we also run checks on your domains so you can see website and mail security status.
Controls
Security baseline
NovaMX uses HTTPS, HSTS, DNSSEC, DANE where applicable, restrictive security headers, monitored infrastructure events, role-based admin access and tracked operational incidents. This page describes technical controls; it is not a legal NIS2 or GDPR compliance certificate.
| Area | What NovaMX does |
|---|---|
| Transport | HTTPS with HSTS on public sites; HTTP redirects to HTTPS |
| DNS | DNSSEC for NovaMX zones; customer DNSSEC when NovaMX DNS is active |
| Browser security | Strict CSP and security headers on portal and marketing hosts |
| Admin access | Role-based admin access with MFA for portal operators |
| Infrastructure | European suppliers for hosting, mail and platform services |
Payments
Checkout and payment methods
You can browse packages and build a cart today. Placing a paid order opens after payment-provider verification. When checkout is open, payments are processed through Mollie.
- Catalog and cart are visible before orders open
- Paid checkout stays blocked until NovaMX enables ordering
- Optional waitlist so we can email you when ordering opens
Monitoring and incident handling
Infrastructure sources send signed events to NovaMX monitoring. Critical findings can create admin incidents and are reviewed by NovaMX operations. Automated remediation is only triggered by an operator where the action is safe and authorized.
Privacy requests
Customers can request data access, correction, export or deletion review through the customer portal. Deletion is reviewed manually because legal retention, billing records and service obligations may apply.
Responsible disclosure
Security researchers can contact NovaMX through the published security.txt information. Please do not access, change or exfiltrate customer data while reporting a vulnerability.
FAQ
Trust questions
Is NovaMX ISO-certified?
We do not claim ISO or similar certifications on this page. We publish technical controls and independent test reports instead of badges we have not earned.
Where can I see outages?
status.novamx.eu shows public component status, maintenance windows and incidents that affect customer services.
How do I report a security issue?
Use the contact details in security.txt. Do not probe customer data or disrupt production while reporting.