Security Standards

Last updated: December 14, 2024

At Nova, security is at the core of everything we do. We employ industry-leading security measures to protect your data and financial information.

Encryption: All data transmitted between your device and our servers is encrypted using TLS 1.3. Sensitive data at rest is encrypted using AES-256 encryption.

Infrastructure Security: Our infrastructure is hosted on SOC 2 Type II certified cloud providers. We implement network segmentation, firewalls, and intrusion detection systems.

Authentication: We support multi-factor authentication (MFA) and encourage all users to enable it. We use secure password hashing algorithms and implement rate limiting to prevent brute force attacks.

Compliance: Nova is compliant with PCI DSS Level 1 for payment card data, SOC 2 Type II for security controls, and GDPR for data protection. We undergo regular third-party security audits.

Incident Response: We have a dedicated security team that monitors for threats 24/7. In the event of a security incident, we have established procedures for rapid response and user notification.

Bug Bounty Program: We maintain a bug bounty program to encourage responsible disclosure of security vulnerabilities. If you discover a security issue, please report it to security@Nova.com.

Security Updates: We regularly update our systems and dependencies to address known vulnerabilities. We recommend keeping your devices and browsers updated for optimal security.