Help Centre Contact Sales
Sign in
Noxtill
Skip to content
SECURITY

Security & Data Protection

Security program, tenant segregation, identity, encryption architecture, incident handling and verifiable evidence.

Version
1.0
Last updated
October 10, 2026
Reading time
2 min

Noxtill LLC · Security & Data Protection · Version 1.0 · noxtill.com/trust/security

AT A GLANCE

  • Defense-in-depth

    Enforce identity verification, least-privilege server-side access, tenant-level segregation, audit trails, secrets management, encryption appropriate to risk, environment separation, secure release pipeline, backups…

  • Incident handling

    Record severity, detection, containment, customer impact, evidence and remediation.

  • Certifications

    Do not publish SOC 2, ISO 27001, PCI DSS, HIPAA or penetration-testing certifications without supporting current evidence.

Security program, tenant segregation, identity, encryption architecture, incident handling and verifiable evidence.

Enforce identity verification, least-privilege server-side access, tenant-level segregation, audit trails, secrets management, encryption appropriate to risk, environment separation, secure release pipeline, backups and incident response; publish only independently verified controls.

Record severity, detection, containment, customer impact, evidence and remediation. Notify affected parties and authorities within contractually and legally applicable times after reasonable assessment; do not promise every incident will meet one universal notification deadline.

Security governance

Noxtill should align its security program to recognized risk-management practices such as NIST Cybersecurity Framework 2.0. The public page describes implemented controls, not aspirational controls.

Tenant isolation

Every request, background job, export, search, webhook and AI/tool call must be scoped to authenticated tenant/business/branch context. Browser-supplied tenant identifiers must never be treated as authorization. Cross-tenant access is prohibited by default and tested.

Identity and access

Use role-based access control, field-level restrictions for sensitive information, least privilege, MFA capability, session controls, staff offboarding and privileged-admin restrictions. High-risk support access should be time-bound, approved and auditable.

Encryption

Use current industry-standard TLS for data in transit. Sensitive data at rest should use appropriate managed database/storage encryption. Keys and secrets should be separated from source code and access-controlled.

Secrets and integrations

OAuth tokens, API keys, webhook secrets and provider credentials must not appear in frontend code, exported workflows, logs or AI prompts. They belong in secure secret storage and canonical Integrations.

Secure development lifecycle

Release gates should include code review, dependency management, secret scanning, authorization/tenant tests, vulnerability scanning, staged deployment and rollback. High-impact money/stock/workflow paths require idempotency and concurrency tests.

Audit logging

Sensitive create/update/delete/status/approval/financial/signature actions should record actor, role, timestamp, entity, before/after summary, source, correlation ID and provider result where relevant.

Backups and recovery

Backups should be encrypted, access-controlled and periodically restore-tested. Noxtill should not publish RPO/RTO or uptime values that are not measured and contractually supported.

Incident response

Maintain severity classification, escalation, containment, evidence preservation, legal/privacy assessment, customer communication and post-incident review. Breach notices follow applicable law and the DPA.

Vulnerability management

Provide a responsible-reporting route and prohibit destructive security testing without authorization. Triage by severity and remediate according to risk. Do not advertise a bug bounty unless one actually exists.

Vendor risk

Critical subprocessors/providers should undergo proportionate risk review. Contracts should address confidentiality, breach notification, access, data return/deletion and subprocessors where applicable.

AI security

AI tools operate through explicit tool schemas and permissions. Defend against prompt injection, tool abuse, data exfiltration and cross-tenant context leakage. Consequential external results require verification.

Customer responsibility

Customers remain responsible for user administration, MFA, endpoints, staff offboarding, API key hygiene, lawful integrations and appropriate role assignment. No security program eliminates all risk.

Questions about this document: support@noxtill.com · Privacy: privacy@noxtill.com · Noxtill LLC, 4539 N 22nd St, Ste R, Phoenix, AZ 85016, United States.

Related documents