Trust Center
See how Noustiq protects your data.
See the main security controls, access safeguards, data-handling practices and verification status. If something is not implemented or independently certified, the page says so clearly.
Last reviewed 26 August 2026. Security contact: hello@noustiq.com
Application controls
| Control | Status | Position | Evidence |
|---|---|---|---|
| CSRF protection | Implemented | State-changing requests carry a token verified server-side. | Confirm before use |
| Content Security Policy | Implemented | Sent on site responses. Executable JavaScript is first-party; the inline JSON-LD block is nonce-authorised. | Confirm before use |
| Security headers | Implemented | nosniff, frame denial, referrer policy, permissions policy and HSTS. | Confirm before use |
| Output escaping | Implemented | All rendered values pass through a single escaping helper. | Confirm before use |
| IP pseudonymisation | Implemented | Submission source addresses are stored as a keyed HMAC, never in the clear. | Confirm before use |
Access and identity
| Control | Status | Position | Evidence |
|---|---|---|---|
| Authentication | Validate per deployment | Application authentication exists. Session, failure-rate and cookie controls must be validated against the deployed application before contracting. | Confirm before use |
| Role-based access control | Validate per deployment | Roles separate research, approval and sales surfaces. Confirm the role matrix against your own separation-of-duties requirement. | Confirm before use |
| Record-level scoping | Validate per deployment | Assigned-record scoping is part of the product model. Validate enforcement against the deployed application and role matrix. | Confirm before use |
| Multi-factor authentication | Not claimed | Not available in this release. | None published |
| SAML single sign-on | Not claimed | Not available in this release. | None published |
| SCIM provisioning | Not claimed | Not available in this release. | None published |
Operations
| Control | Status | Position | Evidence |
|---|---|---|---|
| Audit logging | Validate per deployment | An audit-log capability is part of the application. Validate covered events, retention and export requirements against the deployment. | Confirm before use |
| Backup and recovery | Validate per deployment | Backup, retention and restore controls are deployment-specific and must be validated and documented before a pilot. | Confirm before use |
| Incident response | Not published | No public incident-response summary is published. Incident handling requirements must be documented before contracting. | None published |
| Responsible disclosure | Published | A disclosure route and security contact are published. | View |
| Vulnerability management | Not published | Dependency and platform patching are handled operationally. No public standard. | None published |
Independent verification
| Control | Status | Position | Evidence |
|---|---|---|---|
| Independent penetration test | Not claimed | No third-party test has been commissioned. | None published |
| SOC 2 | Not certified | No certification held. | None published |
| ISO 27001 | Not certified | No certification held. | None published |
| Independent accessibility audit | Not claimed | This site is built and tested against WCAG 2.2 AA. No external audit has been commissioned. | View |
Data and legal
| Control | Status | Position | Evidence |
|---|---|---|---|
| Data processing agreement | Review required | A public data-processing overview is available. An executable DPA still requires legal review and agreement before contracting. | View |
| Subprocessor register | Review required | The public page explains the register structure. The actual deployment-specific subprocessor list must be confirmed before processing begins. | View |
| Data retention standard | Not published | Retention is agreed per deployment and recorded in the agreement. | None published |
| Data residency options | Review required | No general data-residency option is claimed. Hosting region and transfer requirements must be confirmed per deployment. | Confirm before use |
Security review documents
The documents a review usually asks for.
Published documents are linked. Other rows state whether an artifact is unavailable or must be prepared and checked before it is relied on. Nothing is presented as evidence until it exists.
| Document | Owner | Availability | Link |
|---|---|---|---|
| Security OverviewApplication and platform controls, access model, logging. | Security | Not available | — |
| Architecture OverviewComponents, trust boundaries and where customer data rests. | Engineering | Not available | — |
| Data Flow DescriptionHow account and contact data moves through research, approval and handoff. | Engineering | Not available | — |
| Access Control MatrixRoles against the actions and records each can reach. | Security | Not available | — |
| Data Retention StandardRetention periods and deletion on termination. | Security | Not available | — |
| Subprocessor DisclosureHow the deployment-specific subprocessor list is disclosed and maintained. | Legal | Published | Open |
| Data Processing OverviewController and processor issues that must be settled before contracting. | Legal | Published | Open |
| Privacy NoticeWhat this site and the product collect, and why. | Legal | Published | Open |
| Incident Response SummaryDetection, escalation and customer notification. | Security | Not available | — |
| Business Continuity SummaryRecovery objectives and restoration procedure. | Operations | Not available | — |
| Secure Development LifecycleReview, testing and release controls. | Engineering | Not available | — |
| Penetration Test Executive SummaryThird-party assessment findings and remediation. | Security | Not available | — |
Automation and AI
Product AI position
The public website does not make a product-level claim about model-assisted research. Any use of models, providers, retention, training, regions and human-review controls must be disclosed and validated for the deployed application before contracting.
| Operation | Execution | Note |
|---|
Your data
What Noustiq stores and how it is handled.
Noustiq can process business account and contact information inside a customer deployment. Controller and processor roles, instructions and data boundaries must be confirmed in the signed agreement for that deployment.
Found a security issue?
We will not pursue anyone who reports in good faith and gives reasonable time to fix the issue.
Have security or procurement questions?
Send us your questionnaire or requirements. We will answer what is in place today and identify anything that still needs to be confirmed.