Security FAQ for Procurement Teams
You can download this FAQ as a PDF for offline review:
- π¬π§ English Version (PDF)
- π«π· Version FranΓ§aise (PDF)
This document answers the security and compliance questions asked most frequently by enterprise procurement and InfoSec teams during the vendor assessment process. For anything not covered here, contact security@noxys.eu.
Data Residencyβ
Where are customer prompts and metadata stored?
All data processed and stored by Noxys is hosted exclusively within the European Union (EU-West regions) by default. No data is transferred to or stored in third-country infrastructure unless explicitly requested by the customer.
Can we pin our data to a specific region or country?
Yes. Enterprise tier customers may request per-region pinning (e.g., France, Germany, Netherlands) via a Data Processing Agreement addendum. Region pinning is enforced at the storage and inference layers. Contact enterprise@noxys.eu to enable this.
Encryptionβ
How is data encrypted in transit?
All communications between the Noxys browser extension, the management console, and backend APIs use TLS 1.3. TLS 1.2 is accepted for legacy client compatibility but flagged in the admin audit log. Older protocol versions are rejected.
How is data encrypted at rest?
All persisted data (prompt logs, policy metadata, audit events) is encrypted at rest using AES-256-GCM with envelope encryption managed by a cloud KMS. Each tenant's data is encrypted under a separate data-encryption key (DEK) that is itself wrapped by a key-encryption key (KEK) in the KMS.
What is envelope encryption and which KMS is used?
Noxys uses a two-layer envelope encryption scheme: DEK (per-tenant, rotated quarterly) wrapped by a KEK in the cloud KMS. The architecture and rotation policy are defined in the internal KMS-1 ADR (available to Enterprise customers under NDA).
Can we bring our own encryption key (BYOK/CMK)?
Yes. Enterprise tier customers may supply a Customer-Managed Key (CMK) stored in their own cloud KMS (AWS KMS, Azure Key Vault, or GCP Cloud KMS). Noxys never has access to the plaintext CMK. Key revocation immediately renders encrypted data inaccessible. Contact your account manager to enable CMK.
Compliance Certificationsβ
What certifications does Noxys hold?
| Standard | Status |
|---|---|
| SOC 2 Type I | In progress β target completion Q3 2026 |
| GDPR | Compliant β DPA available, see below |
| EU AI Act | Ready β Noxys is designed as a conformity-enabling layer |
| ISO 27001 | Roadmapped β target audit Q1 2027 |
| NIS2 | Architecture aligned; formal assessment planned |
Up-to-date certification status, audit reports, and evidence packages are available via the Trust Center (NDA required for SOC 2 reports).
Is Noxys GDPR-compliant?
Yes. Noxys acts as a Data Processor under GDPR Article 28 on behalf of its customers (the Data Controllers). A standard DPA is available pre-contract. Noxys maintains a Record of Processing Activities (RoPA) and a DPIA template is available on request.
Sub-Processorsβ
Who are Noxys's sub-processors?
| Sub-Processor | Purpose | Location |
|---|---|---|
| Stripe | Payment processing and billing | USA (SCCs in place) |
| Managed PostgreSQL provider | Primary database hosting | EU (France / Germany) |
| Cloud infrastructure provider | Compute, object storage, KMS | EU-West |
| Transactional email provider | Alerts and notifications | EU |
The full, continuously updated sub-processor list β including legal entity names, DPA links, and transfer mechanisms β is maintained at noxys.eu/trust-center/subprocessors. Customers are notified at least 30 days in advance of any new or replacement sub-processor.
Authentication & Access Controlβ
What authentication methods are supported?
- SSO via OIDC: Google Workspace, Microsoft Entra ID (Azure AD), and any generic OIDC provider.
- SAML 2.0: Supported for Enterprise tier customers.
- SCIM 2.0: Provisioning and de-provisioning β in progress, target Q3 2026.
- Local accounts: Available for non-SSO environments; MFA required.
See SSO Configuration and Microsoft Entra ID for setup guides.
What access-control model does Noxys use?
Noxys implements Role-Based Access Control (RBAC) with four built-in roles: Owner, Admin, Analyst, and Read-Only. Custom roles are available on Enterprise tier. Every action is logged in the immutable audit trail.
Can we enforce MFA for all users?
Yes. MFA can be enforced per-tenant from the admin console. Supported second factors: TOTP apps (Authy, Google Authenticator) and WebAuthn/FIDO2 hardware keys.
Data Retentionβ
How long is data retained?
The default retention period for interaction logs (prompt metadata, policy decision records) is 90 days. Customers may configure shorter retention periods down to 7 days from the admin console. Audit logs are retained for 1 year and cannot be shortened below the compliance minimum.
Can we request early deletion of our data?
Yes. A hard-delete request can be submitted via the console (Tenant Settings β Data Management) or by emailing privacy@noxys.eu. Deletion is executed within 72 hours and confirmed in writing. Backup purge completes within 30 days.
Data Processing Agreement (DPA)β
Is a DPA available?
Yes. A standard Noxys DPA (aligned to GDPR Article 28 and EU SCCs for sub-processors) is available pre-contract without charge.
Where can we get the DPA template?
Download the current DPA template from the Trust Center. Enterprise customers requiring custom DPA terms should contact legal@noxys.eu.
Incident Responseβ
What is the notification SLA for security incidents?
Noxys commits to notifying affected customers within 24 hours of confirming a security incident that may impact their data. This notification includes a preliminary impact assessment.
What happens after an incident?
A full post-mortem β including root cause, timeline, remediation actions, and preventive measures β is delivered to affected customers within 7 business days. All incidents affecting personal data are reported to the relevant supervisory authority (CNIL for France) within the GDPR 72-hour window.
Penetration Testingβ
Does Noxys conduct penetration testing?
Yes. An independent third-party penetration test is conducted annually targeting the management console, API layer, browser extension, and infrastructure. The most recent pentest executive summary is available to Enterprise prospects under NDA.
Can we conduct our own penetration test?
Customers may perform black-box testing against their own tenant with 5 business days' prior notice. Contact security@noxys.eu to coordinate scope and timing. Destructive testing and load testing require written approval.
Customer Audit Rightsβ
Can we audit Noxys's security controls?
Enterprise tier customers have the right to:
- Audit log export: Full tenant audit trail exportable in SIEM-compatible formats (CEF, JSON, Splunk HEC).
- On-site audit support: Noxys will make relevant personnel and documentation available for on-site or remote security audits with 10 business days' notice.
- Questionnaire completion: Noxys will complete standard security questionnaires (SIG, CAIQ, bespoke) within 10 business days.
- Evidence packages: SOC 2 reports, pentest summaries, and DPIAs provided on request (NDA required).
Sovereignty & Jurisdictional Protectionβ
Is Noxys immune to extra-territorial surveillance laws (e.g., US CLOUD Act, FISA 702)?
Yes. Noxys is a 100% EU-owned and operated entity. Our infrastructure and software supply chain are decoupled from US-based hyper-scalers. We prioritize hosting on sovereign providers (like OVHcloud or 3DS Outscale) which are not subject to the US CLOUD Act. This ensures your data remains under the exclusive jurisdiction of EU law and the CJEU.
Do you use any US-based subprocessors for core data processing?
No. All core processing (classification, inference, storage) is performed on EU-sovereign infrastructure. Non-core administrative services (like payment processing via Stripe) are strictly sandboxed and subject to standard EU Standard Contractual Clauses (SCCs).
Hosting & Architectureβ
Which hosting providers do you use for sovereign deployments?
By default, Noxys uses OVHcloud (France) and Hetzner (Germany) for production workloads. We also support certified deployments on Azure France Central for customers already within the Microsoft ecosystem who require localized data residency and compliance with French regulation (e.g., for Banking or Healthcare sectors). We do not use US-based regions for any "Sovereign" or "Regulated" tier deployments.
Do you offer an "Air-gapped" or fully on-premise version?
Yes. For governmental or highly sensitive industrial clients, Noxys offers an Air-Gapped Deployment package. This includes local Docker images or a Kubernetes manifest that requires zero outbound internet connectivity to function. Contact sovereign@noxys.eu for technical requirements.
How do you ensure service availability and scaling?
Noxys uses a multi-region, active-active architecture within the EU. Each layer of the stack (API, NATS, PostgreSQL) is clustered and distributed across at least three availability zones. We guarantee 99.9% uptime for Business tier and 99.99% for Enterprise tier.
Software Supply Chain & Vulnerability Managementβ
Do you provide a Software Bill of Materials (SBOM)?
Yes. Noxys generates an SBOM (CycloneDX format) for every release of our API and browser extension. This allows customers to verify all third-party dependencies and their licenses.
What is your SLA for patching critical vulnerabilities?
| Severity | Target Patch Time |
|---|---|
| Critical | < 24 hours |
| High | < 72 hours |
| Medium | < 14 days |
| Low | Next scheduled release |
We use automated SAST/DAST tools (Snyk, Semgrep) integrated into our CI/CD pipelines to catch vulnerabilities before they reach production.
How do you handle browser extension security?
The Noxys extension follows Manifest V3 best practices. It requests the minimum required permissions (declarativeNetRequest, storage). All code is audited for XSS and injection risks. We never inject third-party scripts into the extension context.
Business Continuity & Insuranceβ
What is your backup and recovery policy?
Database backups are taken every hour (point-in-time recovery) and stored in encrypted object storage across multiple EU regions. We conduct quarterly Disaster Recovery (DR) drills to ensure a Recovery Time Objective (RTO) of < 4 hours and a Recovery Point Objective (RPO) of < 1 hour.
Does Noxys carry cyber-liability insurance?
Yes. Noxys maintains a comprehensive Cyber-Liability & Professional Indemnity insurance policy with a coverage limit of β¬5,000,000 per claim. A certificate of insurance can be provided to Enterprise customers on request.
Employee & Operational Securityβ
Do you conduct background checks on your employees?
Yes. All employees with access to production infrastructure or sensitive customer data undergo mandatory background checks, including criminal record verification, in accordance with local labor laws.
Is access to production environments restricted?
Yes. We follow the Principle of Least Privilege (PoLP). Access to production is restricted to a subset of the SRE team and requires:
- Hardware MFA (Yubikey).
- Just-in-Time (JIT) access via a bastion host.
- Full session recording and audit logging.
Still have questions?β
| Contact | Purpose |
|---|---|
| security@noxys.eu | Security assessments, pentest coordination, vulnerability disclosure |
| privacy@noxys.eu | GDPR requests, data deletion, DPA questions |
| legal@noxys.eu | Custom DPA terms, contractual questions |
| enterprise@noxys.eu | Enterprise tier, CMK, region pinning |
Trust Center: noxys.eu/trust-center