trust.

Everything your reviewer will ask for, before they ask. The statements that matter link to the documents that carry them.

what we hold, and what we don't.

we hold

  • company names and domains, as you sent them
  • the public legal-entity identifiers we matched them to
  • public-source findings: filings, register entries, sanctions listings, notices
  • your work email, company name, and the addresses you nominate for alerts

we don't hold

  • no contracts, no spend, no pricing data
  • no questionnaire responses: the companies you watch are never contacted
  • no credentials, API keys or access into your systems
  • no user accounts: there is no portal and no login

The worst case, if every system we run were compromised, is that an attacker gets company names, domains, public identifiers and some business email addresses. No credentials, no integrations, no path into your network, because none was ever built. That is the case for registering us at a lower tier than a vendor with production access.

That list still matters. Each of those facts is public on its own. Your list of which companies matter most to you is not: it's your concentration risk written down, and its value isn't the sum of its parts. We treat a breach of it as a confidentiality incident and would tell you so.

How long we hold it is in the privacy policy, with one number worth pulling out here: a list from someone who doesn't become a customer is deleted within 90 days, without you having to ask.

where your data is processed.

  • The service runs on a server in Canada, operated by OVH and contracted through OVH's Polish entity. Backups in Canada and Warsaw.
  • Language models are Anthropic, xAI, OpenAI and Google, in the United States. They see company names and public-source material; they do not train on it.
  • Mail is split: Google (Workspace) receives what you send to us and holds it in the EU, with the data region set to Europe, and Resend sends the alerts from the US. Your list arrives in that mailbox, so it sits in the EU before it ever reaches Canada. Cloudflare fronts the site from its global network, the public pages only, so no customer list, finding or alert passes through it.
  • Transfers rely on the EU adequacy decision for Canada plus standard contractual clauses, and on standard contractual clauses for US providers. The adequacy decision covers organisations subject to PIPEDA; the Quebec provincial law where OVH's Canadian capacity sits doesn't hold adequacy in its own right, which is why the clauses sit alongside the decision.
  • There is no EEA processing option. If your policy requires EU-only hosting, we don't meet it today.

Full detail: sub-processors · security summary

certifications.

No ISO 27001 and no SOC 2 today, and nothing on this page should be read as implying otherwise. We are working toward ISO 27001, with SOC 2 to follow. The providers underneath us are independently audited, and you should check their attestations on their own trust pages rather than take our word for them; the sub-processor list links each one.

Those reports cover the platforms underneath us. The self-hosted database and pipeline running on top of the server are not yet covered by an independent audit, and closing that gap is what ISO 27001 is for.

the documents.

  1. security summary: what we hold, where it runs, controls, incidents, continuity
  2. sub-processors: every company involved, where, and on what transfer basis
  3. data processing agreement: the operative terms, including breach notification within 24 hours of our becoming aware, and deletion on exit
  4. privacy policy: including how we handle personal data in public registers
  5. cookie notice: the site sets no cookies of its own and runs no analytics
  6. what we read: the public record of our sources

Ask and we'll also send a redacted sample export, so your audit function can read the real output rather than a description of it. One standard security questionnaire per year is answered free.

check it yourself.

  • The site loads nothing from another server and sets no cookies of its own: view source, and watch the network panel.
  • TLS on noctovisor.com: any browser.
  • Our entity: Noctovisor – Piotr Bogdanowicz, REGON 146596070, EU VAT ID PL5262736443, D-U-N-S® Number 427695885, verifiable in the Polish business register, the EU VAT validation service, and the D&B database.

reporting a vulnerability.

Email contact@noctovisor.com with "security" in the subject line and it gets read first. You'll get an acknowledgement and a straight answer about whether it's being fixed and roughly when. Good-faith research is welcome within limits: don't test the live alert pipeline, don't run denial-of-service tests, don't submit another company's list, and don't touch data that isn't yours.


Version 1.4, 26 August 2026. Send whatever this page fails to answer to contact@noctovisor.com and you'll get a written reply.