Security

Built for IT to approve.

These are the principles we work to on every migration, integration and automation, whichever platforms you use. They are not certifications. Your IT team can review every one of them before anything changes.

Principle 1

Your accounts. Agreed data flows.

Work runs in your own accounts, whether that is Microsoft 365, Google Workspace, Azure, a database or a business app. Before anything starts, we document which data is read, where it goes and which tools touch it. Any external AI processing needs your approval. We do not keep your business records on Nuovix systems.

Principle 2

Least-privilege access

Each migration tool, integration or workflow gets only the permissions it needs, using a dedicated service account where the platform supports one. The list is agreed with your IT team before access is granted. Migration access is time-limited and removed when the project ends.

Principle 3

Data moved, not collected

In a migration, data is copied from your old system to your new one, not stored by us along the way. Counts are checked on both sides before cutover. Where AI is used, we choose services whose terms exclude training on your data and name the provider, locations and retention settings in the proposal.

Principle 4

Documentation handover

At handover you receive what changed, where things live now, the access that was used and has been removed, and how to operate or switch off anything we built. Dependencies and ongoing platform costs are listed.

Also built in

Safe by design, in practice.

Good habits that apply to every build.

A human in the loopApproval steps wherever a mistake would be costly, such as money, contracts or messages to customers.
A way backEvery cutover has a rollback step agreed before it starts.
Pilot firstA small group or sample data set is moved or tested before real records at scale.
You hold the keysCredentials and workflows are held by you and can be revoked at any time.
What this page is not

No badges, no overclaiming.

Nuovix does not claim any security certification or audit. If your organisation needs a particular standard met, say so on the first call and we will tell you plainly whether we can work within it. Questions from your IT team are welcome at [email protected].

Bring your IT team to the first call.

15 minutes, no slides. If automation is not the right answer, we will say so.

Request a 15-minute call
Or email [email protected]