Security and Responsible Disclosure
Security controls implemented for the Australia platform and how to report an issue.
Internally approved for implementation. This document is not represented as externally signed, professionally approved or approved for live Australia service activation.
Implemented controls
The platform uses server-side authorization, role separation, row-level database controls, short-lived access links, log redaction, append-only audit events and environment-level activation gates.
Sensitive document upload remains disabled until encryption, malware scanning, retention and approval checks pass in the production environment.
Report an issue
Send a concise report to security@nova-group.co. Do not include real passport data or exploit customer records.
No unsupported assurance
This page describes implemented controls. It does not claim a certification, audit result or professional approval that has not been completed.