Noetis — Security & Compliance Addendum
Version 2.0 · Effective date: to be announced upon release · Last updated: to be announced upon release
This Addendum describes Noetis's security programme and supports the DPA.
Noetis may modify individual controls as technology and threats evolve provided the overall level of protection is not materially reduced.
Statements in this Addendum distinguish between controls that are designed, implemented, enabled in production and production-certified. A description of a control's design or intent is not a warranty, and a control is not represented as production-certified unless current production evidence supports that claim.
1. Security programme
Noetis maintains an information-security programme proportionate to the nature, scale and risks of the Service.
The programme includes policies and controls addressing:
- access;
- secure development;
- change management;
- incident response;
- backup and recovery;
- secrets;
- vulnerabilities;
- retention;
- suppliers.
2. Encryption
Noetis uses encrypted transport for production Service communications using industry-standard TLS.
Production data stores use encryption-at-rest capabilities provided by the applicable infrastructure providers.
Designated sensitive fields may additionally use application-level encryption.
Noetis maintains key-management and access practices appropriate to the relevant implementation.
3. Access control
Noetis maintains controls designed to restrict production and Customer Data access to authorised users and personnel according to legitimate operational need.
Controls may include:
- role-based access;
- least privilege;
- authentication controls;
- MFA for designated privileged access;
- ownership/authorisation checks;
- tenant-isolation controls.
Administrative access is restricted and subject to appropriate logging.
4. Tenant isolation
Noetis maintains logical tenant-isolation controls designed to prevent one Customer from accessing another Customer's protected resources.
Controls may operate at database, application and API layers.
Noetis maintains automated security testing intended to detect classes of authorisation defects before deployment.
5. Logging and monitoring
Noetis maintains logging and monitoring appropriate to the Service.
Depending on the event type, this may include:
- security events;
- administrative activity;
- important data changes;
- scheduled-job health;
- supplier failures;
- anomalous activity.
Logging scope and retention may vary according to operational necessity and risk.
6. Secure development
Noetis uses a version-controlled development process with automated quality and security controls.
These may include:
- type checking;
- automated tests;
- authorisation/security tests;
- dependency scanning;
- code review;
- input validation;
- AI-content sanitisation;
- deployment controls.
The existence of automated tests does not constitute a warranty that software is defect-free.
7. Vulnerability management
Noetis monitors relevant dependencies and security information and prioritises remediation based on severity, exploitability and risk.
Noetis maintains a vulnerability-reporting channel.
Independent security testing may be commissioned as the security programme develops.
Noetis will not represent itself as holding a certification or audit report until that certification or report has actually been obtained and remains valid.
8. Backups and recovery
Noetis uses managed backup and recovery capabilities appropriate to relevant production systems.
Recovery capabilities are intended to support business continuity and disaster recovery.
Noetis does not warrant zero data loss under every conceivable failure scenario unless expressly committed in a signed Order.
9. Incident response
Noetis maintains an incident-response process addressing:
- identification;
- severity;
- containment;
- investigation;
- recovery;
- communication;
- post-incident review.
Personal Data Breaches are handled in accordance with the DPA.
10. Visitor Intelligence safeguards
Noetis maintains privacy and security controls designed to support safe operation of Visitor Intelligence, which may include:
- consent-state enforcement designed so that only a supported affirmative consent state activates consent-dependent processing;
- pseudonymous identifiers;
- tenant isolation;
- profile deletion/suppression;
- restrictions designed to prevent sensitive inference;
- access controls;
- decision/event logging.
The availability and implementation of particular controls may depend on feature configuration.
11. AI and autonomous-system safeguards
Noetis may maintain:
- semantic-safety gates;
- source-of-truth restrictions;
- immutable-content controls;
- confidence thresholds;
- fail-closed states where configured;
- rollback;
- experiment controls;
- spend/rate controls;
- audit records.
These controls reduce risk but do not eliminate the probabilistic nature of AI. Instructions given to an AI model are not, by themselves, a hard enforcement boundary.
12. Personnel
Personnel with access to sensitive systems or Customer Data are subject to confidentiality requirements.
Access is granted according to role and operational need and may be reviewed periodically.
13. Suppliers
Noetis assesses and contracts with subprocessors and infrastructure providers appropriate to their role.
Data-processing obligations are governed by the DPA.
14. Retention and deletion
Noetis maintains retention and deletion controls appropriate to different data classes.
Operational retention periods may differ between:
- raw behavioural events;
- session data and Visitor Identifiers;
- Visitor Profiles and Derived Data;
- session recordings and heatmap/interaction information;
- Personalisation Records and decision records;
- experiment assignments and outcomes;
- consent/preference information;
- security and application logs;
- AI request metadata, stored prompts and AI Outputs;
- deletion/suppression records;
- backups.
The authoritative operational retention schedule records, per data class, the applicable default, configurability, bounds, deletion trigger and method, and backup expiry, and is populated as values are verified against production. Unverified values are marked as verification pending rather than guessed.
Noetis may adjust retention defaults as the Service evolves, subject to Customer configuration, contractual commitments and applicable law.
15. Compliance posture
Noetis is designed with GDPR compliance requirements in mind.
This statement does not constitute certification by a supervisory authority.
Any future SOC 2, ISO or similar status shall only be represented as achieved after the applicable independent process has been completed.
Noetis maintains, or is completing verification of, the operational compliance registers referenced in the DPA: a retention schedule, a cookie and storage register, a subprocessor register and an international transfer register.
16. Customer responsibilities
Customer is responsible for:
- credentials;
- account permissions;
- Customer-side integrations;
- Customer content;
- lawful configuration;
- consent and notices;
- Optimisation Boundaries;
- accurate source information;
- appropriate review of high-risk use cases.
17. No absolute security guarantee
No security programme can eliminate all risk.
Except where expressly agreed otherwise, Noetis does not warrant that the Service is immune from every vulnerability, attack, outage or loss event.
Security contact: chris@noetis.nl