← All policies

Security & Compliance

Version 2.0 · effective 8/6/2026

What changed: Consolidated catalog: separate policies merged into this document. No protections were removed.

This page is maintained by NovakOS. It describes the controls the platform actually provides — it is not a certification or independent audit.

Encryption

  • All traffic between your devices and NovakOS is encrypted in transit using HTTPS/TLS.
  • Data stored in the database and in file storage is encrypted at rest by our infrastructure providers.
  • Sensitive integration credentials, such as a company's messaging provider keys, are encrypted with a separate application key before being stored.
  • The offline work cache on a device is cleared on sign-out so a shared or lost device does not retain company data.

Backups and recovery

  • The production database is backed up automatically by our infrastructure provider with point-in-time recovery.
  • Company deletion is reversible for 30 days before the permanent purge, which protects against accidental loss.
  • Restores are tested against a separate staging environment, never against live company data.

Access controls

  • Every record is scoped to the company that owns it and enforced at the database level, so one company cannot read another company's data.
  • Within a company, roles (owner, administrator, dispatcher, office, accountant, technician) control what each person can see and change, including payroll and location history.
  • Sensitive actions — viewing or exporting location history, exporting company data, support access to an account — are recorded in an audit trail visible to the company owner.
  • NovakOS staff do not browse company data casually. Any support access to a company's records is recorded in the sensitive access audit with who accessed it and when.

Payment security

  • Full card numbers and CVVs are never stored by NovakOS. Card entry is handled directly by our payment processor.
  • NovakOS stores only the card brand, last four digits, expiry and a processor token.
  • Customer card payments settle into each company's own connected payment account.
  • Storing card numbers or card images in notes, photos or forms is prohibited by the Terms of Service.

Canadian data handling

NovakOS is built for Canadian trades businesses and is operated to Canadian privacy expectations (PIPEDA, provincial privacy law, and CASL for messaging consent). Some cloud infrastructure providers process data outside Canada; that is disclosed in the Privacy Policy, and contractual protections are in place with each provider.

Reporting a vulnerability

Send security reports to security@novakos.org. Include steps to reproduce, the affected URL or screen, and the time of testing. We acknowledge reports and keep the reporter updated through resolution.

Responsible disclosure guidelines

  • Test only against accounts you own or have permission to test.
  • Do not access, modify, or exfiltrate another company's data.
  • Do not run denial-of-service, spam, or social-engineering tests.
  • Give us reasonable time to fix an issue before disclosing it publicly.

How we respond to incidents

  • Incidents are logged with affected data categories, affected companies, timeline, containment steps and notification status.
  • Evidence is preserved before remediation where it is safe to do so.
  • Affected companies are notified when an incident presents a real risk of significant harm, along with any regulator notification required by law.

Support and contact

  • Security: security@novakos.org
  • Privacy: privacy@novakos.org
  • General support: support@novakos.org
  • Billing questions: billing@novakos.org
  • In-app: the Help section includes an error-code lookup for anything you see on screen.
  • When contacting support, include your company name, the email you sign in with, any error code shown (for example E1203), and what you expected versus what happened.