Skip to content
TTermnova
ProductSecurityLegal
GitHubOpen workspace
Legal centerOverviewPrivacyTermsCookiesAcceptable useSecurityData processingSubprocessorsData rightsAccessibility

Trust by evidence

Security Overview

A factual view of the controls built into Termnova today, the settings customers must configure, and the assurances that are not yet claimed.

Reviewed September 18, 2026Hosted public beta
No unsupported certification claims.

Termnova does not currently claim SOC 2, ISO 27001, FedRAMP, HIPAA, PCI DSS, or other independent certification. This page describes product controls; it is not an audit report or warranty.

Identity and access

  • Production can require authenticated access using revocable API credentials or OIDC browser sign-in.
  • Organization memberships, roles, permissions, workspace scopes, and service accounts support least-privilege access.
  • Browser sessions store a digest server-side and use HttpOnly cookies that are Secure in production; credentials are not written to localStorage or page source.
  • OIDC sign-in uses authorization code flow, PKCE, state, and nonce validation. Enterprise SSO and SCIM require customer configuration.

Tenant and data isolation

  • Tenant identifiers are carried through stored documents and derived records.
  • Application authorization and PostgreSQL row-level security provide layered tenant boundaries for covered tables.
  • Cross-tenant isolation tests run in CI. Customers must still configure identity claims and memberships correctly.

Data protection

  • Transport encryption is provided through HTTPS in hosted production.
  • Original documents can use S3-compatible object storage with provider-side encryption. Secure-upload mode refuses startup unless durable storage and malware scanning are configured.
  • Uploaded files are subject to size, MIME, extension, and content checks; ClamAV scanning is supported for production quarantine workflows.
  • Secrets and selected personal data can be detected or redacted before model use, but automated detection is assistive and may miss sensitive content.
  • Retention policies, deletion workflows, legal holds, immutable-style audit events, and background-job replay controls are available.

AI and provider boundaries

Prompts, retrieved passages, contract text, and derived content may be sent to the model and embedding providers configured for the deployment. Provider geography, logging, retention, training, and abuse-monitoring terms are governed by those providers and the customer agreement. Termnova does not promise universal zero retention across every configurable provider.

Customers evaluating sensitive or regulated data should select approved providers, review their terms, minimize transmitted content, and document an appropriate human-review process.

Operations and secure delivery

  • CI runs quality, package, PostgreSQL integration, container, migration, dependency, and CodeQL checks.
  • Requests use timeouts, retries, rate limits, tenant budgets, structured logging, and trace hooks where configured.
  • Asynchronous jobs support idempotency, processing snapshots, retries, and dead-letter handling.
  • Production telemetry is designed to avoid exposing provider secrets or raw credentials; operators must avoid placing secrets in logs or support messages.

Customer responsibilities

Security is shared. Customers are responsible for identity-provider security, correct role assignment, prompt deprovisioning, lawful uploads, provider selection, endpoint and browser security, integration credentials, source-document backups, and reviewing outputs before action.

Report a vulnerability or incident

Send an initial report through the private operator contact form with a safe description and contact method. Do not include live credentials, exploit customer data, or publicly disclose an unresolved vulnerability. Security questionnaires and signed terms can be requested through the same channel.

T
TermnovaRead the contract. Control what follows.
PrivacyTermsCookiesSecurityLegal centerSign in

Not legal advice. Material contract decisions require qualified review. © 2026 Termnova.