SSL Labs: transport-layer encryption
Run by Qualys, the industry-standard test for TLS configuration. The grade reflects cipher suites, protocol versions, certificate chain, HSTS, and known vulnerabilities. A+ requires HSTS with preload + includeSubDomains and modern TLS only.
Mozilla Observatory: web security headers
The standard test for HTTP security headers: Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, HSTS, Referrer-Policy, Permissions-Policy, cookie security, redirection. A+ requires 10/10 tests passed.
How we encrypt your data
| Data type | In transit | At rest | Per-tenant isolation | Backups |
|---|---|---|---|---|
| Client documents (passports, decisions, attachments) | TLS 1.3 | AES-256 encrypted storage, plus a second layer of field encryption with rotating keys | Yes, scoped to your firm on every read | Continuous (30-day point-in-time recovery) |
| Database rows (clients, cases, conversations) | TLS 1.3 | AES-256 (encrypted database) | Yes, scoped to your firm on every read | Continuous |
| Sessions and authentication tokens | TLS 1.3 | Signed session tokens with a rotating secret | N/A (session-scoped) | N/A (regenerated on rotation) |
| Third-party integration credentials | TLS 1.3 | Per-tenant encrypted at rest | Yes | Continuous |
| Mobile cache (Aurora iOS + Android) | TLS 1.3 | iOS Keychain + Android Keystore (platform-managed) | N/A (single-user device) | N/A (re-fetched on resume) |
| AI request & response logs (metering only, no message content) | TLS 1.3 | AES-256 (encrypted database) | Yes, scoped to your firm | Continuous |
What else protects your data
- Firm isolation: every record belongs to one firm, and the server enforces that on every read. We cannot accidentally surface Firm A's data to Firm B.
- Rate limiting: every public entry point has request limits, so no one can hammer the platform or run up your bill.
- Audit log: every administrative action, every AI call, every authentication event is logged with timestamp, actor, and IP.
- Session security: sessions are signed, expire on a fixed schedule, and can be revoked by the firm owner at any time.
- Encryption-key rotation: a documented rotation procedure.
- Monitoring: failures are recorded and reviewed, so a problem gets caught before you have to report it.
- Disaster recovery: a monthly recovery drill and 30-day point-in-time recovery.
Compliance posture
For our current compliance status (PIPEDA, BC PIPA, Quebec Law 25, GDPR, UK GDPR, CCPA, and SOC 2 Type II readiness) see the Compliance Attestations page. For the sub-processors we use to deliver the platform, see Sub-processors. For the data-protection agreement firms sign, see the Data Processing Addendum.
Reporting a security issue
Email security@thenovasystem.com. We acknowledge within one business day and coordinate disclosure with researchers. Our security contact details are published in .well-known/security.txt per RFC 9116.