Novo Agents Security

Security measures for Novo Agents and how to report concerns.

Last updated: September 23, 2026

Novo Agents Security

Last updated: September 23, 2026

We use technical and organizational measures designed to protect Novo Agents and Customer Data. No system is completely secure.

Our measures

  • Data is encrypted in transit and at rest. Credentials you provide are also encrypted by the application and are not returned by the API.
  • Customer Data is scoped to a workspace, and API keys are scoped to a single workspace.
  • AI provider credentials stay in Novo-managed infrastructure and are not sent to environments you host.
  • Agent file and shell work runs in isolated environments: Novo-managed sandboxes or environments you host.
  • Requests to environments you host, result handlers, and approval hooks are signed so you can verify they came from Novo.
  • We monitor the Service for errors and abuse.

Your responsibilities

Keep API keys secret, limit who can access your workspace, and secure the systems you connect.

Reporting

Report suspected vulnerabilities to security@novoindustries.co.