Skip to main content

Security

Last updated: 1 October 2026 ยท Version 1.0

This page describes how Nova protects the data you connect. It states what we do today, in plain language. The commitments that are contractual are set out in our Data Processing Agreement, and this page points to the relevant section each time.

Where your data is hosted

The Nova application, its databases and the analytics warehouse run on Scaleway infrastructure in the Paris region, France. Network traffic to the application passes through Cloudflare, which acts as a proxy and web application firewall. Backup copies are held in Western Europe.

Our website, novadata.io, is hosted separately from the application. The full list of providers that may process data on our behalf, and the transfer safeguard that applies to each of them, is on our Sub-processors page. We tell customers at least thirty days before adding or replacing any provider on that list.

Encryption

Data is encrypted in transit. The application database is encrypted at rest. The analytics warehouse runs on dedicated servers in France rather than on shared cloud infrastructure.

How Nova connects to Amazon

You authorise Nova through Amazon's own consent screens in Seller Central, Vendor Central and Amazon Ads. Nova never receives and never stores your Amazon password. You can revoke the authorisation directly from Amazon at any time, without going through us.

Nova does not request Amazon's restricted buyer data. We do not receive buyer names, email addresses, phone numbers or shipping addresses, and we do not use Restricted Data Tokens. The only buyer information we keep for an order is its identifier and its country of delivery, which is what the VAT treatment depends on.

Read access, and what it takes to write

A connected account is read-only by default. Nova pulls reports and metrics from Amazon and writes nothing back.

Listing edits stay off until a workspace owner turns them on. When they are on:

  • only a workspace owner can enable them or use them;
  • the change is prepared first and shown to you as a before and after;
  • nothing reaches Amazon until you confirm it;
  • prices and stock levels are never changed;
  • a single edit is capped at fifty SKUs, and every edit is recorded.

The Nova MCP Connector

The connector is how an AI assistant such as Claude, ChatGPT or Gemini reads your Nova data. It is scoped to your Nova account and exposes only your own data.

  • Access uses OAuth authentication or a personal access token.
  • Tokens are stored as a SHA-256 hash, never in readable form. The secret is shown once, when the token is created.
  • Any token can be revoked from Nova at any time, and the revocation takes effect immediately.
  • Requests are rate limited.
  • Every call to the connector is logged, including the account it read.
  • You can disable or delete the connector from your assistant's settings at any time.

Accounts and internal access

  • Passwords are stored as a salted scrypt hash and compared in constant time. We never hold them in readable form.
  • Email verification is required before the first password login, and sign-in attempts are limited.
  • Sign-in with Google is available, so you can avoid a separate password altogether.
  • Inside Nova, access to production data is limited to the team members who need it for support or operations, and they are bound by confidentiality obligations.

Monitoring and backups

We run error monitoring and infrastructure monitoring on the application. The databases are backed up regularly, with an off-site copy of the analytics database in Western Europe.

Keeping your data, and deleting it

You can export your data at any time while your subscription is active, and at the end of it, using the export features in the app.

We delete customer personal data no later than thirty days after a trial that is not followed by a subscription, and no later than sixty days after a subscription ends, unless you have asked for more time to export or the law requires us to keep it. Copies held in backups go as those backups are overwritten on their normal cycle, and we confirm the deletion in writing on request. These are contractual commitments, in Section 10 of the Data Processing Agreement.

If something goes wrong

If a personal data breach affects your data, we notify you without undue delay and in any case no later than forty-eight hours after becoming aware of it, with the information available at that point, and we follow up as we learn more. The full process is Section 9 of the Data Processing Agreement.

Certifications and security reviews

Nova does not hold SOC 2 or ISO 27001 certification today. We are a French company subject to the GDPR, and our Article 28 obligations are set out in the Data Processing Agreement, which includes your right to ask us for the information needed to verify our compliance. If your procurement process requires a security questionnaire, write to [email protected] and we will complete it.

Reporting a security problem

If you believe you have found a vulnerability, email [email protected] with enough detail for us to reproduce it. We will acknowledge your report and keep you informed while we work on it.

We will not pursue legal action against anyone who reports a problem in good faith, provided they do not access, modify or delete anyone else's data, do not degrade the service for others, and give us a reasonable period to fix the issue before making it public.

Contact

Security issues: [email protected] ยท Personal data: [email protected] ยท General questions: [email protected]