Skip to main content

Security FAQ for Procurement Teams

Download PDF Version

You can download this FAQ as a PDF for offline review:

This document answers the security and compliance questions asked most frequently by enterprise procurement and InfoSec teams during the vendor assessment process. For anything not covered here, contact security@noxys.eu.


Data Residency​

Where are customer prompts and metadata stored?

All data processed and stored by Noxys is hosted exclusively within the European Union (EU-West regions) by default. No data is transferred to or stored in third-country infrastructure unless explicitly requested by the customer.

Can we pin our data to a specific region or country?

Yes. Enterprise tier customers may request per-region pinning (e.g., France, Germany, Netherlands) via a Data Processing Agreement addendum. Region pinning is enforced at the storage and inference layers. Contact enterprise@noxys.eu to enable this.


Encryption​

How is data encrypted in transit?

All communications between the Noxys browser extension, the management console, and backend APIs use TLS 1.3. TLS 1.2 is accepted for legacy client compatibility but flagged in the admin audit log. Older protocol versions are rejected.

How is data encrypted at rest?

All persisted data (prompt logs, policy metadata, audit events) is encrypted at rest using AES-256-GCM with envelope encryption managed by a cloud KMS. Each tenant's data is encrypted under a separate data-encryption key (DEK) that is itself wrapped by a key-encryption key (KEK) in the KMS.

What is envelope encryption and which KMS is used?

Noxys uses a two-layer envelope encryption scheme: DEK (per-tenant, rotated quarterly) wrapped by a KEK in the cloud KMS. The architecture and rotation policy are defined in the internal KMS-1 ADR (available to Enterprise customers under NDA).

Can we bring our own encryption key (BYOK/CMK)?

Yes. Enterprise tier customers may supply a Customer-Managed Key (CMK) stored in their own cloud KMS (AWS KMS, Azure Key Vault, or GCP Cloud KMS). Noxys never has access to the plaintext CMK. Key revocation immediately renders encrypted data inaccessible. Contact your account manager to enable CMK.


Compliance Certifications​

What certifications does Noxys hold?

StandardStatus
SOC 2 Type IIn progress β€” target completion Q3 2026
GDPRCompliant β€” DPA available, see below
EU AI ActReady β€” Noxys is designed as a conformity-enabling layer
ISO 27001Roadmapped β€” target audit Q1 2027
NIS2Architecture aligned; formal assessment planned

Up-to-date certification status, audit reports, and evidence packages are available via the Trust Center (NDA required for SOC 2 reports).

Is Noxys GDPR-compliant?

Yes. Noxys acts as a Data Processor under GDPR Article 28 on behalf of its customers (the Data Controllers). A standard DPA is available pre-contract. Noxys maintains a Record of Processing Activities (RoPA) and a DPIA template is available on request.


Sub-Processors​

Who are Noxys's sub-processors?

Sub-ProcessorPurposeLocation
StripePayment processing and billingUSA (SCCs in place)
Managed PostgreSQL providerPrimary database hostingEU (France / Germany)
Cloud infrastructure providerCompute, object storage, KMSEU-West
Transactional email providerAlerts and notificationsEU

The full, continuously updated sub-processor list β€” including legal entity names, DPA links, and transfer mechanisms β€” is maintained at noxys.eu/trust-center/subprocessors. Customers are notified at least 30 days in advance of any new or replacement sub-processor.


Authentication & Access Control​

What authentication methods are supported?

  • SSO via OIDC: Google Workspace, Microsoft Entra ID (Azure AD), and any generic OIDC provider.
  • SAML 2.0: Supported for Enterprise tier customers.
  • SCIM 2.0: Provisioning and de-provisioning β€” in progress, target Q3 2026.
  • Local accounts: Available for non-SSO environments; MFA required.

See SSO Configuration and Microsoft Entra ID for setup guides.

What access-control model does Noxys use?

Noxys implements Role-Based Access Control (RBAC) with four built-in roles: Owner, Admin, Analyst, and Read-Only. Custom roles are available on Enterprise tier. Every action is logged in the immutable audit trail.

Can we enforce MFA for all users?

Yes. MFA can be enforced per-tenant from the admin console. Supported second factors: TOTP apps (Authy, Google Authenticator) and WebAuthn/FIDO2 hardware keys.


Data Retention​

How long is data retained?

The default retention period for interaction logs (prompt metadata, policy decision records) is 90 days. Customers may configure shorter retention periods down to 7 days from the admin console. Audit logs are retained for 1 year and cannot be shortened below the compliance minimum.

Can we request early deletion of our data?

Yes. A hard-delete request can be submitted via the console (Tenant Settings β†’ Data Management) or by emailing privacy@noxys.eu. Deletion is executed within 72 hours and confirmed in writing. Backup purge completes within 30 days.


Data Processing Agreement (DPA)​

Is a DPA available?

Yes. A standard Noxys DPA (aligned to GDPR Article 28 and EU SCCs for sub-processors) is available pre-contract without charge.

Where can we get the DPA template?

Download the current DPA template from the Trust Center. Enterprise customers requiring custom DPA terms should contact legal@noxys.eu.


Incident Response​

What is the notification SLA for security incidents?

Noxys commits to notifying affected customers within 24 hours of confirming a security incident that may impact their data. This notification includes a preliminary impact assessment.

What happens after an incident?

A full post-mortem β€” including root cause, timeline, remediation actions, and preventive measures β€” is delivered to affected customers within 7 business days. All incidents affecting personal data are reported to the relevant supervisory authority (CNIL for France) within the GDPR 72-hour window.


Penetration Testing​

Does Noxys conduct penetration testing?

Yes. An independent third-party penetration test is conducted annually targeting the management console, API layer, browser extension, and infrastructure. The most recent pentest executive summary is available to Enterprise prospects under NDA.

Can we conduct our own penetration test?

Customers may perform black-box testing against their own tenant with 5 business days' prior notice. Contact security@noxys.eu to coordinate scope and timing. Destructive testing and load testing require written approval.


Customer Audit Rights​

Can we audit Noxys's security controls?

Enterprise tier customers have the right to:

  1. Audit log export: Full tenant audit trail exportable in SIEM-compatible formats (CEF, JSON, Splunk HEC).
  2. On-site audit support: Noxys will make relevant personnel and documentation available for on-site or remote security audits with 10 business days' notice.
  3. Questionnaire completion: Noxys will complete standard security questionnaires (SIG, CAIQ, bespoke) within 10 business days.
  4. Evidence packages: SOC 2 reports, pentest summaries, and DPIAs provided on request (NDA required).

Sovereignty & Jurisdictional Protection​

Is Noxys immune to extra-territorial surveillance laws (e.g., US CLOUD Act, FISA 702)?

Yes. Noxys is a 100% EU-owned and operated entity. Our infrastructure and software supply chain are decoupled from US-based hyper-scalers. We prioritize hosting on sovereign providers (like OVHcloud or 3DS Outscale) which are not subject to the US CLOUD Act. This ensures your data remains under the exclusive jurisdiction of EU law and the CJEU.

Do you use any US-based subprocessors for core data processing?

No. All core processing (classification, inference, storage) is performed on EU-sovereign infrastructure. Non-core administrative services (like payment processing via Stripe) are strictly sandboxed and subject to standard EU Standard Contractual Clauses (SCCs).


Hosting & Architecture​

Which hosting providers do you use for sovereign deployments?

By default, Noxys uses OVHcloud (France) and Hetzner (Germany) for production workloads. We also support certified deployments on Azure France Central for customers already within the Microsoft ecosystem who require localized data residency and compliance with French regulation (e.g., for Banking or Healthcare sectors). We do not use US-based regions for any "Sovereign" or "Regulated" tier deployments.

Do you offer an "Air-gapped" or fully on-premise version?

Yes. For governmental or highly sensitive industrial clients, Noxys offers an Air-Gapped Deployment package. This includes local Docker images or a Kubernetes manifest that requires zero outbound internet connectivity to function. Contact sovereign@noxys.eu for technical requirements.

How do you ensure service availability and scaling?

Noxys uses a multi-region, active-active architecture within the EU. Each layer of the stack (API, NATS, PostgreSQL) is clustered and distributed across at least three availability zones. We guarantee 99.9% uptime for Business tier and 99.99% for Enterprise tier.


Software Supply Chain & Vulnerability Management​

Do you provide a Software Bill of Materials (SBOM)?

Yes. Noxys generates an SBOM (CycloneDX format) for every release of our API and browser extension. This allows customers to verify all third-party dependencies and their licenses.

What is your SLA for patching critical vulnerabilities?

SeverityTarget Patch Time
Critical< 24 hours
High< 72 hours
Medium< 14 days
LowNext scheduled release

We use automated SAST/DAST tools (Snyk, Semgrep) integrated into our CI/CD pipelines to catch vulnerabilities before they reach production.

How do you handle browser extension security?

The Noxys extension follows Manifest V3 best practices. It requests the minimum required permissions (declarativeNetRequest, storage). All code is audited for XSS and injection risks. We never inject third-party scripts into the extension context.


Business Continuity & Insurance​

What is your backup and recovery policy?

Database backups are taken every hour (point-in-time recovery) and stored in encrypted object storage across multiple EU regions. We conduct quarterly Disaster Recovery (DR) drills to ensure a Recovery Time Objective (RTO) of < 4 hours and a Recovery Point Objective (RPO) of < 1 hour.

Does Noxys carry cyber-liability insurance?

Yes. Noxys maintains a comprehensive Cyber-Liability & Professional Indemnity insurance policy with a coverage limit of €5,000,000 per claim. A certificate of insurance can be provided to Enterprise customers on request.


Employee & Operational Security​

Do you conduct background checks on your employees?

Yes. All employees with access to production infrastructure or sensitive customer data undergo mandatory background checks, including criminal record verification, in accordance with local labor laws.

Is access to production environments restricted?

Yes. We follow the Principle of Least Privilege (PoLP). Access to production is restricted to a subset of the SRE team and requires:

  1. Hardware MFA (Yubikey).
  2. Just-in-Time (JIT) access via a bastion host.
  3. Full session recording and audit logging.

Still have questions?​

ContactPurpose
security@noxys.euSecurity assessments, pentest coordination, vulnerability disclosure
privacy@noxys.euGDPR requests, data deletion, DPA questions
legal@noxys.euCustom DPA terms, contractual questions
enterprise@noxys.euEnterprise tier, CMK, region pinning

Trust Center: noxys.eu/trust-center