Trust Center

What auditors, DPOs and CISOs want to know before the pilot.

Security policies, compliance mappings and architecture documentation for Nova IAM: 13 public documents, readable without an NDA or sign-up.

Who you are and where to start

Current compliance status

Each item below shows whether it is done, in progress or planned.

NIS-2 / NIS2UmsuCG
In force since 6 December 2025 · Sec. 30 BSIG risk management · Sec. 32 BSIG reporting · IAM mapping
Documented
Cyber Resilience Act (CRA)
Reporting obligations under Art. 14 apply since 11 September 2026 · further obligations from 11 December 2027 · Vulnerability management · SBOM
In progress
GDPR / DSGVO
Article mapping for controllers
Mapping documented
Audit log
Log of who, when and from where · Schema versioned
Implemented
Access Control (RBAC)
Role model · Inheritance · Provisioning control
Documented
Vulnerability Disclosure
Public policy · Safe harbour · Acknowledgement within 2 business days
Active
ISO/IEC 27001
No certificate. We will announce the date of the certification audit once a certification body has been engaged.
No date yet
SOC 2 Type 1
No SOC 2 report. Planned after ISO 27001, no fixed date (see roadmap).
After ISO 27001
External penetration test
We will announce the date once it is contractually fixed · results under NDA with pilot customers
Date to follow
Maturity: We do not hold any certifications yet. What we can demonstrate today is set out in 13 public documents; open items are listed in the status above.

Policies and compliance documents

13 public documents: policies, compliance mappings and architecture. Click to read or download as Markdown source.

CISO Security

Security Policy

Security controls, authentication, data protection, audit logging.

Read →
CISO Auditor

Architecture Security Overview

System architecture, security boundaries, data flows and controls matrix. For technical evaluators and pen testers.

Read → Architecture overview →
DPO Legal

Data Protection Policy

Data categories, processing principles, third-party sharing, breach notification procedures.

Read →
DPO EU

GDPR Compliance

Article-by-article GDPR mapping, DPA framework, international data transfers.

Read →
CISO EU NIS-2

NIS-2 Compliance Mapping

Mapping to NIS-2 Articles 21 and 23 and Sections 30 and 32 BSIG, IAM as NIS-2 control instrument, evidence for authorities and auditors.

Read →
CISO EU CRA

Cyber Resilience Act

CRA classification, Annex I requirements, vulnerability management, SBOM, ENISA reporting and CE conformity timeline.

Read →
Auditor Compliance

Audit Trail Documentation

Audit log schema, event categories, integrity and limits, regulatory mapping.

Read →
Security Auditor

Access Control Policy

RBAC model, inheritance rules, provisioning controls, account lifecycle management.

Read →
DevOps Engineering

Deployment Security Guide

Production hardening, TLS setup, network security, monitoring.

Read →
CISO Operations

Incident Response Plan

Detection, containment, eradication, recovery, communication procedures.

Read →
Security Public

Vulnerability Disclosure Policy

Reporting process, timelines, safe harbor, credit for researchers.

Read →
Engineering Auditor

Change Management Policy

Change categories, review process, deployment standards, migration security.

Read →
Sales Legal

SLA Template

Support response times; availability, backup/recovery and service credits only for the planned hosted variant.

Read →

Complete compliance pack

All documents as ZIP bundle, for audit preparation, RFP responses or internal due diligence.

Request pack

Regulatory coverage

Which regulations our documents relate to, with the status from the overview above. A reference does not replace a certificate or an audit report.

Regulation Relevant documents Status
NIS-2 / NIS2UmsuCG NIS-2 Compliance · Access Control · Audit Trail · Incident Response Documented
Cyber Resilience Act Cyber Resilience Act · Security Policy · Vulnerability Disclosure · Change Management In progress
GDPR / DSGVO GDPR Compliance · Data Protection · Incident Response Mapping documented
ISO/IEC 27001 Security Policy · Architecture Security · Access Control · Change ManagementWhat the documents relate to, not a certificate No date yet
SOC 2 Security Policy · Audit Trail · Access Control · Change ManagementWhat the documents relate to, not a SOC 2 report After ISO 27001

Contact

Security reports

security@nova-iam.com

Acknowledgement within 2 business days, initial assessment within 5 business days, safe harbour under our Vulnerability Disclosure Policy. Machine-readable contact details: /.well-known/security.txt

Privacy

privacy@nova-iam.com

Data subject access, rectification, deletion and complaint requests.

Trust & Compliance

trust@nova-iam.com

Compliance pack requests, audit evidence, architecture walkthrough for evaluators.