Skip to main content

Trust Center

Security, privacy, and evidence by design

Novatria embeds controls across Governance and Security suites and exposes evidence needed for continuous assurance.

Security Practices

  • Encryption in transit (TLS 1.3) and at rest (AES-256)
  • Least-privilege role enforcement across all API and UI access
  • Security headers (CSP, HSTS, X-Frame-Options) on every surface
  • WAF and rate-limiting policies at the edge
  • Secret scanning in CI/CD pipelines

Privacy & Data Protection

  • GDPR-aligned data processing and retention controls
  • HIPAA compliance controls for healthcare workloads
  • Data classification and sensitivity labeling
  • Tenant-level data isolation with separate databases per suite

Audit & Evidence

  • Immutable audit logging for every mutation
  • Policy-driven evidence collection across both suites
  • Compliance framework mapping (SOC 2, ISO 27001, NIST, GDPR)
  • On-demand evidence pack generation for auditors

Operational Resilience

  • Standardized SLO dashboards across all four surfaces
  • Automated incident drill schedule and reporting
  • Disaster recovery and backup-restore verification
  • Cross-app telemetry correlation with request IDs

Ready to see the evidence?

Book a demo to see how Novatria generates audit-ready evidence across governance and security workflows.