Security controls
How Noxys protects data across the platform, mapped to the SOC 2, ISO 27001 and GDPR control families. Noxys does not hold a SOC 2 or ISO 27001 certification today; an audit is planned.
Audit logging
Tamper-evident, append-only audit log of policy decisions, admin actions and data access.
Tenant isolation
PostgreSQL Row-Level Security enforced on every tenant-scoped table.
Encryption at rest and in transit
TLS 1.3, AES-256-GCM, per-tenant KMS keys and X25519 envelope encryption.
Rate limiting and DoS protection
Per-tenant and per-endpoint limits, backed by Cloudflare WAF and DDoS protection.
PII detection and classification
Microsoft Presidio-based detection extended with Noxys-specific recognizers.
Data minimization
Salted SHA-256 hashing of prompts by default; raw retention is strictly opt-in.