Trust Center

See how Noustiq protects your data.

See the main security controls, access safeguards, data-handling practices and verification status. If something is not implemented or independently certified, the page says so clearly.

Last reviewed 26 August 2026. Security contact: hello@noustiq.com

Application controls

ControlStatusPositionEvidence
CSRF protectionImplementedState-changing requests carry a token verified server-side.Confirm before use
Content Security PolicyImplementedSent on site responses. Executable JavaScript is first-party; the inline JSON-LD block is nonce-authorised.Confirm before use
Security headersImplementednosniff, frame denial, referrer policy, permissions policy and HSTS.Confirm before use
Output escapingImplementedAll rendered values pass through a single escaping helper.Confirm before use
IP pseudonymisationImplementedSubmission source addresses are stored as a keyed HMAC, never in the clear.Confirm before use

Access and identity

ControlStatusPositionEvidence
AuthenticationValidate per deploymentApplication authentication exists. Session, failure-rate and cookie controls must be validated against the deployed application before contracting.Confirm before use
Role-based access controlValidate per deploymentRoles separate research, approval and sales surfaces. Confirm the role matrix against your own separation-of-duties requirement.Confirm before use
Record-level scopingValidate per deploymentAssigned-record scoping is part of the product model. Validate enforcement against the deployed application and role matrix.Confirm before use
Multi-factor authenticationNot claimedNot available in this release.None published
SAML single sign-onNot claimedNot available in this release.None published
SCIM provisioningNot claimedNot available in this release.None published

Operations

ControlStatusPositionEvidence
Audit loggingValidate per deploymentAn audit-log capability is part of the application. Validate covered events, retention and export requirements against the deployment.Confirm before use
Backup and recoveryValidate per deploymentBackup, retention and restore controls are deployment-specific and must be validated and documented before a pilot.Confirm before use
Incident responseNot publishedNo public incident-response summary is published. Incident handling requirements must be documented before contracting.None published
Responsible disclosurePublishedA disclosure route and security contact are published.View
Vulnerability managementNot publishedDependency and platform patching are handled operationally. No public standard.None published

Independent verification

ControlStatusPositionEvidence
Independent penetration testNot claimedNo third-party test has been commissioned.None published
SOC 2Not certifiedNo certification held.None published
ISO 27001Not certifiedNo certification held.None published
Independent accessibility auditNot claimedThis site is built and tested against WCAG 2.2 AA. No external audit has been commissioned.View

Data and legal

ControlStatusPositionEvidence
Data processing agreementReview requiredA public data-processing overview is available. An executable DPA still requires legal review and agreement before contracting.View
Subprocessor registerReview requiredThe public page explains the register structure. The actual deployment-specific subprocessor list must be confirmed before processing begins.View
Data retention standardNot publishedRetention is agreed per deployment and recorded in the agreement.None published
Data residency optionsReview requiredNo general data-residency option is claimed. Hosting region and transfer requirements must be confirmed per deployment.Confirm before use

Security review documents

The documents a review usually asks for.

Published documents are linked. Other rows state whether an artifact is unavailable or must be prepared and checked before it is relied on. Nothing is presented as evidence until it exists.

DocumentOwnerAvailabilityLink
Security OverviewApplication and platform controls, access model, logging.SecurityNot available
Architecture OverviewComponents, trust boundaries and where customer data rests.EngineeringNot available
Data Flow DescriptionHow account and contact data moves through research, approval and handoff.EngineeringNot available
Access Control MatrixRoles against the actions and records each can reach.SecurityNot available
Data Retention StandardRetention periods and deletion on termination.SecurityNot available
Subprocessor DisclosureHow the deployment-specific subprocessor list is disclosed and maintained.LegalPublishedOpen
Data Processing OverviewController and processor issues that must be settled before contracting.LegalPublishedOpen
Privacy NoticeWhat this site and the product collect, and why.LegalPublishedOpen
Incident Response SummaryDetection, escalation and customer notification.SecurityNot available
Business Continuity SummaryRecovery objectives and restoration procedure.OperationsNot available
Secure Development LifecycleReview, testing and release controls.EngineeringNot available
Penetration Test Executive SummaryThird-party assessment findings and remediation.SecurityNot available

Automation and AI

Product AI position

The public website does not make a product-level claim about model-assisted research. Any use of models, providers, retention, training, regions and human-review controls must be disclosed and validated for the deployed application before contracting.

OperationExecutionNote
No product-level AI capability claim is made by this website. Validate the deployed application before contracting.

Your data

What Noustiq stores and how it is handled.

Noustiq can process business account and contact information inside a customer deployment. Controller and processor roles, instructions and data boundaries must be confirmed in the signed agreement for that deployment.

Deployment isolation
Validate per deploymentApplication, database and tenant boundaries are confirmed before production processing.
Deployment region
Chosen per customerConfirm before contracting.
Retention
Agreed per deploymentRecorded in the agreement, not set by us unilaterally.
Bulk export
Constrained by designExport scope is deliberately limited as an exfiltration control.
Website submissions
Pseudonymised at sourceSource addresses are stored as a keyed HMAC, never in the clear.
Subprocessors
Confirm per deploymentThe public disclosure explains the process; the actual list is confirmed before production processing.

Found a security issue?

We will not pursue anyone who reports in good faith and gives reasonable time to fix the issue.

Security contact
hello@noustiq.com
Policy
PublishedScope, expectations and response times.
security.txt
/.well-known/security.txt

Read the disclosure policy

Have security or procurement questions?

Send us your questionnaire or requirements. We will answer what is in place today and identify anything that still needs to be confirmed.