Trust Center
Straight answers about your data
What we do today, who handles your data, and what we haven't done yet. We only list what we've verified.
Last reviewed October 2026
What we do today
Encrypted in transit
All traffic uses HTTPS (TLS 1.2 and 1.3; older versions are disabled) with HSTS enabled.
Credentials encrypted before storage
Integration credentials (Slack, Teams, ConnectWise, Kaseya, Autotask tokens) and phone numbers are encrypted with AES-256-GCM before they are saved in our database.
Sign-in handled by a specialist
Sign-in, passwords and optional multi-factor authentication are handled by Clerk. We never see or store your password.
Strict separation between customers
Every request is checked on the server and scoped to your organization. One customer's data is never returned to another.
Admin-only for sensitive actions
Deleting the organization, managing API keys, SSO, billing and exports are limited to organization admins, and are not available to API keys.
Audit trail
Changes are recorded in an audit log you can review. Actions by our staff in the admin portal are logged separately.
Abuse protection
Rate limiting, signature checks on Slack, Stripe and Twilio callbacks, protection against server-side request forgery on outbound webhooks, and a strict content security policy.
Backups, tested
Nightly database backups, plus an automated restore test every week to prove they actually work.
Monitored from the outside
Health checks every few minutes, an independent outside-in uptime check, and a public status page.
Dependency scanning
Every change is automatically checked for known-vulnerable dependencies before it is released.
Retention and deletion
Raw alert events are deleted after 90 days and audit logs after 1 year. Organization admins can delete their organization and its data at any time; contact us for an export.
What we're still working on
We'd rather tell you than have you find out. These are not in place yet:
- SOC 2 certification — not yet started with an auditor, so nothing is certified.
- An independent penetration test.
- Full-disk encryption of our database server and backups.
- Off-site copies of backups.
- Enforced multi-factor authentication for every customer account (it is available through Clerk, but not mandatory).
Who processes your data
Our subprocessors, and when each one is involved.
| Provider | What for | When |
|---|---|---|
| DigitalOcean | Hosting and database (New York, USA) | Always |
| Clerk | Sign-in and user accounts | Always |
| SendGrid (Twilio) | Sending email notifications | When email notifications are used |
| Twilio | SMS and voice notifications | When SMS or voice notifications are used |
| Expo | Mobile push notifications | When the mobile app is used |
| Sentry | Error monitoring | Always |
| Anthropic | AI features (Ask NOCBuddy, incident summaries, optional AI triage) | Only when you use an AI feature or turn on AI triage |
| Slack / Microsoft Teams | Delivering alerts to your chat | Only if you connect them |
| Stripe | Payment processing | When paid billing is enabled |
Security questions, a vulnerability to report, or a data request? Email security@nocbuddy.com.