Security Approach
Owner-controlled actions
During controlled pilot use, consequential customer-facing actions can remain approval-gated. NovaAceTech is designed to prepare context and recommended next steps without silently releasing high-impact actions simply because AI proposed them.
Least-privilege access
Connections should be limited to the services, accounts, and data needed for the approved workflow. Access can vary by pilot configuration and integration.
Traceability
Where supported by the workflow, NovaAceTech aims to keep the draft, reason, state, and owner decision visible so actions can be reviewed instead of disappearing into opaque automation.
Data minimization
We aim to avoid collecting or connecting information that is not needed for the approved business workflow.
Provider and account security
NovaAceTech depends on external hosting, email, cloud, AI, and communications providers. Customers are responsible for maintaining secure credentials and multifactor authentication on their own accounts where available.
Payments and sensitive financial services
The current public website does not custody customer funds, operate a wallet, or provide financial advice. Any future payment workflow would use an approved third-party provider and would be separately evaluated before release.
Report a security concern
If you believe you found a security issue involving NovaAceTech, email hello@novaacetech.ai with a concise description, affected page or workflow, reproduction steps, and impact. Please do not access, modify, or retain data that does not belong to you.
Report a security concern →