TermsPrivacySubprocessorsDPASecurityIntegrations
Sign inGet started
Draft: not yet reviewed by a lawyer

Novix is pre-launch. This document is a working draft written to describe what the product actually does today. It has not been reviewed by an attorney and is not legal advice. We will replace it with a counsel-reviewed version before general availability.

Legal

Security and vulnerability disclosure

Effective August 20, 2026Contact support@getnovix.ai

If you have found a vulnerability in Novix, please tell us before telling anybody else. This page is what /.well-known/security.txt points at.

How to report

Email support@getnovix.ai. Tell us what you found, how to reproduce it, and what you think the impact is. A rough report beats no report: if you are not sure whether something counts, send it anyway.

If a report contains customer data you came across, say so and do not attach it. We will work out what we need.

What we commit to

Novix is a small company, so this is short and it is all true:

  • We acknowledge your report within three working days.
  • We tell you what we found when we have looked, and what we are going to do about it.
  • We tell you when it is fixed.
  • We credit you by name or handle if you want that, and stay quiet about you if you do not.
  • We will not pursue or support legal action against you for research done in line with this page.

There is no bounty programme and no payment. We would rather say that plainly than imply one exists.

In scope

  • getnovix.ai and app.getnovix.ai, including the API under /api.
  • The embeddable chat widget and the hosted report form.
  • The published packages @novix-ai/cli and @novix-ai/mcp-server.
  • Anything about how Novix handles a workspace’s code, tickets, credentials or attachments, including one workspace reaching another’s data.

Out of scope

  • Our vendors’ own products. Report those to them; the list is on subprocessors.
  • Anything requiring physical access, a stolen device, or social engineering of our staff or customers.
  • Denial of service, load testing, and automated scanning heavy enough to affect other people. Please do not.
  • Reports from a scanner with no working proof, and findings that are configuration opinions rather than a way in.
  • A tool connected to Novix by a customer behaving as that customer configured it. That is their setting, not our bug.

Please do not

  • Access, change or keep data that is not yours. If you reach somebody else’s data by accident, stop, and tell us what you saw.
  • Run anything destructive, or anything that degrades the service.
  • Publish the details until it is fixed, or until 90 days have passed and we have gone quiet. If we are slow, say so and we will agree a date.

What we already do

So you know where to look, and because a security questionnaire asks:

  • A person approves every code change. Novix opens a pull request and stops. It never merges on its own.
  • Credentials are encrypted at rest and are never mixed between workspaces.
  • Attachments are in a private bucket, reachable only through Novix’s own token-scoped routes.
  • No third-party analytics script runs on the pages that render other companies’ customer tickets. Our product analytics are first-party.
  • Every privileged action is in an audit log that nothing in the product can edit or delete.
  • A drafted fix runs in a throwaway container, never on our own machines or yours.

What we do with data, and who else touches it, is on privacy and subprocessors.

What we do not have

We do not hold a SOC 2 report, an ISO 27001 certificate, or any other third-party security or accessibility audit. Novix is small enough that you would be reading an audit of a handful of people. If your review needs one, tell us where you are in your process and we will tell you honestly where we are, rather than implying we have something we do not.

We also have no bug bounty, which is above, and no dedicated security team. One person reads this mailbox.

If something does go wrong

There is a written procedure and we read it before we need it. If an incident touches data we hold for a workspace, we tell that customer without undue delay with what they need to meet their own obligations. If it touches Novix account data, we are the controller and we notify the people affected, and a supervisory authority within 72 hours where the law requires it. The full version is in the privacy policy and our DPA.

Novix© 2026 · getnovix.ai
TermsPrivacySubprocessorsDPASecurityIntegrations