Skip to main content
Security

Security questions deserve direct answers.

Review where source code lives, what an AI provider can receive, how credentials are handled and when Nova needs a person to approve an action.

Short answers

The questions your review will ask.

Where is the working copy?
In the engineering environment selected for the project, either customer-owned or managed by NovaCore.
Does any code reach an AI provider?
Yes. Relevant source excerpts and tool results may be included in model input. The full repository does not need to move.
Does the AI provider receive credentials?
No. Credentials are not included in prompts or model responses.
How is connected access limited?
Repository and service access is scoped to the projects and actions Nova needs for the assigned work.
What decides whether an action happens?
Your configured rules determine whether Nova may proceed, must ask a named approver or is blocked.
Can an approval be reused?
No. Approval applies to the specific action and target shown to the reviewer.
How are customers separated?
Customer data is logically isolated, and sensitive stored content is encrypted.
Can we see what happened?
Nova retains a visible history of the work, approvals, usage, verification and final result.
Controls

What Nova enforces.

Safeguardsconfigured by your team
Customer isolation

Every request is scoped to one customer, and stored data remains separated between customers.

Content encryption

Sensitive content is encrypted in storage and protected in transit.

Minimal AI context

Nova sends the configured AI provider only the context needed for the current task; credentials stay out.

Approval rules

Sensitive actions pause for the right person, while prohibited actions remain blocked.

Recorded outcomes

Nova records what was requested, what was approved and what the connected service returned.

Environment security

Customer-owned and managed environments have explicit access, network and operational responsibilities.

Data flow

What stays put, and what crosses.

01 · Engineering environment

Repository checkout, build caches, project toolchain, browser state and narrowly scoped development access.

02 · AI provider

Task instructions, relevant excerpts and bounded tool results when needed for the work.

03 · Nova

Work history, approvals, usage, project guidance and selected verification evidence.

04 · Connected services

Only the scoped credentials and actions configured for Jira, GitHub or another approved service.

“Your code never leaves” would be misleading for a product that can use hosted AI providers. The repository stays in the selected engineering environment, while relevant excerpts and results may be sent for the current task. Credentials are not sent to the AI provider.

Limitations

What we are not claiming.

stated deliberately

AI can still be wrong

Rules limit authority; they do not make reasoning infallible. Verification and human review remain part of the operating model.

stated deliberately

Allowed context is still disclosure

If a source excerpt is sent for AI processing, the configured provider receives it. Provider terms and retention therefore matter.

stated deliberately

An approved action can have impact

Approval means the action is allowed, not risk-free. Scope, service permissions and downstream controls still matter.

stated deliberately

The work environment is powerful

Isolation, patching and network reach depend on who operates it. Managed and customer-owned environments have different shared responsibilities.

Deployment

Shared service or dedicated deployment.

Standard

A shared NovaCore service with customer isolation and encrypted sensitive content. Work can run in your engineering environment or one managed by NovaCore.

Enterprise

Dedicated deployment, private networking, tailored retention and security review are available where the operating requirement justifies them.

Ask about a required certification or control framework early. We will describe current evidence and gaps directly rather than using a generic trust badge.

Send this to your security team.

Then bring back the questions about AI-provider data flow, environment responsibility, credential custody and approval rules. Those are the useful ones.