Your business data,protected by design.
Security is built into the foundation of NovaHQ — not added as an afterthought. Here's how we protect your business information.
Organisation-based data isolation
Every organisation's data is separated. Users in one organisation cannot access another organisation's records — enforced at the database level.
Role-based access control
Granular permissions control who can create, read, update and delete records within each organisation, based on assigned roles.
Secure OAuth 2.0 integrations
Third-party connections use OAuth 2.0 with fixed scopes and PKCE. Provider passwords are never stored; authorisation tokens are encrypted at rest and can be revoked.
Australian compliance
Built for Australian businesses with GST compliance, AUD currency, Australian timezones, and adherence to the Privacy Act 1988.
Encrypted data transmission
All data is transmitted over HTTPS with TLS encryption. Authentication tokens are managed securely by the platform.
Data ownership
You own your data. You can export it at any time, and upon account closure, we help you retrieve everything before deletion.
How we handle your data.
Transparent practices for how your business information is stored, accessed and protected.
Who can see your data
- Only users you invite to your organisation
- Access controlled by role-based permissions
- Customer portal users only see what you share
- Employee portal users only see their assigned jobs
Your data rights
- Export your data at any time
- Delete your account and data on request
- Control which integrations are connected
- Revoke OAuth access at any time
Have security questions?
We're happy to discuss our security practices in detail. Contact us for enterprise security inquiries.
