Security
Last updated: July 24, 2026
Our Security Commitment
Novaonyx is built from the ground up to deliver post-quantum security for the enterprise. Our platform protects voice, text, and attachments across mobile, desktop, and integrated systems — maintaining security as communications move across different devices and network types.
Post-Quantum Cryptography
All Novaonyx services are secured using NIST-standardized post-quantum cryptographic algorithms, designed to resist attacks from both classical and quantum computers:
- CRYSTALS-Kyber (ML-KEM): NIST-standardized key encapsulation mechanism used for quantum-resistant key exchange across all data transmissions
- CRYSTALS-Dilithium (ML-DSA): NIST-standardized digital signature algorithm used for authentication and data integrity verification
- Hybrid Key Exchange: Combines classical ECDH with CRYSTALS-Kyber for defense-in-depth during the transition to full post-quantum security
Zero-Knowledge Architecture
Our platform is designed so that Novaonyx cannot access your data:
- End-to-end encryption ensures communication content is encrypted on the sender's device and can only be decrypted by the intended recipient
- We do not store, process, or have access to encryption keys or plaintext content
- Key generation and management occur entirely on client devices
- Zero-knowledge proofs enable authentication without exposing credentials
Infrastructure Security
- SOC 2 Type II compliant infrastructure
- Data encrypted at rest using AES-256 with quantum-resistant key wrapping
- Real-time threat detection and anomaly monitoring
- Regular third-party penetration testing and security audits
- Geographic redundancy across multiple availability zones
- Automated key rotation with configurable intervals
Compliance & Certifications
- GDPR: Full compliance with EU data protection regulations
- SOC 2 Type II: Independently audited security controls
- ISO 27001: Information security management certification
- NIST PQC Standards: Implementation aligned with NIST FIPS 203, 204, and 205
- HIPAA: Healthcare data protection capabilities available
Vulnerability Disclosure
We welcome responsible disclosure of security vulnerabilities. If you discover a security issue, please report it to our security team. We commit to:
- Acknowledging receipt of your report within 24 hours
- Providing a status update within 72 hours
- Working with you to understand and address the issue
- Recognizing your contribution (with your permission) in our security advisory
Contact Our Security Team
For security inquiries, vulnerability reports, or compliance questions, please reach out: