Skip to content
Version 2026-08-05.internal-1External professional approval pending

Security and Responsible Disclosure

Security controls implemented for the Australia platform and how to report an issue.

Internally approved for implementation. This document is not represented as externally signed, professionally approved or approved for live Australia service activation.

Implemented controls

The platform uses server-side authorization, role separation, row-level database controls, short-lived access links, log redaction, append-only audit events and environment-level activation gates.

Sensitive document upload remains disabled until encryption, malware scanning, retention and approval checks pass in the production environment.

Report an issue

Send a concise report to security@nova-group.co. Do not include real passport data or exploit customer records.

No unsupported assurance

This page describes implemented controls. It does not claim a certification, audit result or professional approval that has not been completed.