Legal

Security and trust

Technical security posture and responsible disclosure information.

Security baseline

NovaMX uses HTTPS, HSTS, DNSSEC, DANE where applicable, restrictive security headers, monitored infrastructure events, role-based admin access and tracked operational incidents.

Monitoring and incident handling

Infrastructure sources send signed events to NovaMX monitoring. Critical findings can create admin incidents and are reviewed by NovaMX operations.

Privacy requests

Customers can request data access, correction, export or deletion review through the customer portal.

Responsible disclosure

Security researchers can contact NovaMX through the published security.txt information. Please do not access, change or exfiltrate customer data while reporting a vulnerability.