Aller au contenu principal

Transparency

Noxys publishes quarterly transparency reports detailing what data is processed, how long it is retained, who can access it, and what we have committed to not doing with it. This page is the index; individual reports are linked below.

Quarterly reports

  • Q2 2026 (current) — pre-production template, public commitments and metric placeholders
  • Q3 2026 — to be published 2026-09-30

Standing commitments

Independent of any quarterly report, Noxys commits to:

  1. No raw prompt storage — prompts are processed in-memory and only structured metadata is persisted (see the Q2 2026 report for the full taxonomy).
  2. EU data residency — all processing in Frankfurt (eu-central-1) and OVH Gravelines.
  3. Sub-processor disclosure — every sub-processor listed publicly with country of operation and DPA link, see legal/sub-processors.
  4. Right of audit — Enterprise customers may inspect our infrastructure logs under NDA, on request.
  5. Pre-disclosure of incidents — security incidents affecting customer data disclosed within 72h of detection, ahead of legal minimums.

Methodology

  • Numbers are aggregated from telemetry that does not include prompt content.
  • Pre-production reports use placeholder data marked TODO — these will be replaced with real numbers once Noxys reaches GA.
  • Definitions follow the Noxys Glossary.

Contact