Security
Security is part of how NOVARIS designs technology, manages information, and develops its systems.
Our approach begins with a simple principle: access to information and capabilities should be limited to the people, systems, and contexts that are expressly authorized.
Our Approach
We design our systems with principles such as:
- identity- and permission-based access control;
- separation between users, organizations, and operational contexts;
- protection of information in transit;
- controlled management of credentials and secrets;
- traceability of relevant actions;
- application of the principle of least privilege;
- validation and review of sensitive changes;
- separation between development and production environments;
- monitoring and response to security events;
- continuous review of risks as our products evolve.
Applicable measures may vary depending on the service, product, or stage of development.
Security by Design
NOVARIS is building its ecosystem with security as part of the architecture, not as a layer added afterward.
This includes designing controls to limit access between organizations, protect sensitive operations, and retain sufficient evidence of relevant actions when appropriate.
Future capabilities that remain in Concept status should not be interpreted as controls that are already implemented or available.
Report a Security Issue
If you believe you have identified a vulnerability or security issue related to NOVARIS, contact:
security@novarissolution.com
Official security reporting information is also available at: /.well-known/security.txt
We appreciate good-faith security reports. We ask that researchers avoid actions that may affect the availability of our systems, modify or delete information, unnecessarily access third-party data, or exceed what is reasonably necessary to identify and report an issue.
Transparency
NOVARIS will only publish certifications, audits, compliance standards, or formal security commitments when they can be supported by verifiable evidence.
As our products and operations evolve, this page may be updated to reflect controls and commitments that have been formally implemented.

