Trust

Security and trust

Technical controls, independent tests and clear company details. This page describes how NovaMX runs, not a compliance certificate.

Company

Who you are dealing with

NovaMX B.V. is a Dutch company. You can verify our registration details below and reach us through the published contact channels.

Independent tests

Public scores for novamx.eu

These reports are for our own website and mail infrastructure. In My NovaMX we also run checks on your domains so you can see website and mail security status.

Controls

Security baseline

NovaMX uses HTTPS, HSTS, DNSSEC, DANE where applicable, restrictive security headers, monitored infrastructure events, role-based admin access and tracked operational incidents. This page describes technical controls; it is not a legal NIS2 or GDPR compliance certificate.

Area What NovaMX does
Transport HTTPS with HSTS on public sites; HTTP redirects to HTTPS
DNS DNSSEC for NovaMX zones; customer DNSSEC when NovaMX DNS is active
Browser security Strict CSP and security headers on portal and marketing hosts
Admin access Role-based admin access with MFA for portal operators
Infrastructure European suppliers for hosting, mail and platform services

Payments

Checkout and payment methods

You can browse packages and build a cart today. Placing a paid order opens after payment-provider verification. When checkout is open, payments are processed through Mollie.

Monitoring and incident handling

Infrastructure sources send signed events to NovaMX monitoring. Critical findings can create admin incidents and are reviewed by NovaMX operations. Automated remediation is only triggered by an operator where the action is safe and authorized.

Privacy requests

Customers can request data access, correction, export or deletion review through the customer portal. Deletion is reviewed manually because legal retention, billing records and service obligations may apply.

Responsible disclosure

Security researchers can contact NovaMX through the published security.txt information. Please do not access, change or exfiltrate customer data while reporting a vulnerability.

FAQ

Trust questions

Is NovaMX ISO-certified?

We do not claim ISO or similar certifications on this page. We publish technical controls and independent test reports instead of badges we have not earned.

Where can I see outages?

status.novamx.eu shows public component status, maintenance windows and incidents that affect customer services.

How do I report a security issue?

Use the contact details in security.txt. Do not probe customer data or disrupt production while reporting.