Security & Privacy
Overview
NOCT secures its own infrastructure to the same standards it helps you achieve. Your data is protected by design, with strict data isolation and least-privilege access as core principles. All data is stored and handled in the United States.
Security model
- Strict data isolation & least privilege - every customer is an isolated tenant with tightly restricted, role-based, audited access to their data.
- Encryption in transit and at rest - scan artifacts, credentials, and sensitive metadata are encrypted both in transit and at rest.
- AES-256 + XOR credential protection - cached server credentials and IP:port information are encrypted with AES-256 and wrapped in an XOR-based hash stream; credentials are retrieved only when operationally required.
- Encrypted scan results - results are stored AES-256-encrypted and decrypted only upon explicit, authenticated request through the dashboard.
- In-memory-only credential processing - scan engines run in segregated execution environments and decrypt customer credentials in RAM only for the duration of an execution window; they are never persisted in plaintext.
Framework alignment
Controls are aligned with the SOC 2 Trust Service Criteria (NOCT is not SOC 2 certified), designed in accordance with ISO/IEC 27001 principles (NOCT does not hold ISO/IEC 27001 certification), and informed by NIST cybersecurity best practices and industry-standard security controls.
AI security guarantees
All AI runs on NOCT's own local servers, never a third-party provider. No AI is ever trained on your data. All AI usage is fully stateless, and only anonymized security findings are processed - no customer or asset data.
Privacy by default
NOCT collects only the minimum data required to perform authorized security testing. Customer data is never sold, shared, or repurposed; it is used exclusively to deliver the requested services and is governed by strict internal access controls and full auditing of all data access.