Legal
Security and trust
Technical security posture and responsible disclosure information.
Security baseline
NovaMX uses HTTPS, HSTS, DNSSEC, DANE where applicable, restrictive security headers, monitored infrastructure events, role-based admin access and tracked operational incidents.
Monitoring and incident handling
Infrastructure sources send signed events to NovaMX monitoring. Critical findings can create admin incidents and are reviewed by NovaMX operations.
Privacy requests
Customers can request data access, correction, export or deletion review through the customer portal.
Responsible disclosure
Security researchers can contact NovaMX through the published security.txt information. Please do not access, change or exfiltrate customer data while reporting a vulnerability.