Trust · Security

Security at Nous

Nous holds your most sensitive revenue data, so confidentiality, integrity, and availability are built into how the service runs. Identity, storage, and payments are handled by providers independently certified for exactly that job.

SOC 2 infrastructure Encrypted at rest & in transit Open source & self-hostable
Built on
Supabase
Our managed Postgres database and hosting. SOC 2 Type 2 certified, with encryption at rest, daily backups, and point-in-time recovery — the platform hundreds of thousands of teams already trust.
Clerk
Authentication and session security. Multi-factor sign-in, passkeys, and device management come built in, so account access is protected by far more than a password.
Stripe
All billing and payments. Stripe is a PCI DSS Level 1 Service Provider, the highest certification in the industry, so card data never touches our systems.
Controls

Multi-factor authentication

Sign-in runs on Clerk, so every account can be locked down with multi-factor authentication, passkeys, and device checks — not just a password.

Powered by Clerk

Data encryption

Every request is served over TLS, and data is encrypted at rest. Sensitive credentials like OAuth tokens are additionally encrypted at the application layer with AES-256 before they ever reach the database.

Role-based access control

Access to production and customer data follows least privilege and need-to-know. Every operator has a unique account, access is reviewed regularly, and it's revoked the moment a role changes.

Backups & recovery

The production database is backed up every day, with point-in-time recovery available. We test restores and rebuild from reproducible, container-defined infrastructure.

Powered by Supabase

Payment processing

Billing runs entirely on Stripe and Nous never stores your card details. Stripe holds PCI DSS Level 1, the highest certification in payments.

Powered by Stripe

SOC 2 infrastructure

Nous Cloud is hosted on Supabase, which is SOC 2 Type 2 certified. The controls behind the platform we build on are independently audited every year.

Powered by Supabase

Your data is yours

We use your data only to run the service. We never sell it, and we never train shared or cross-customer models on it. Export any time; delete your workspace and the records are gone.

Open source & self-hosting

The core of Nous is open source. Run the whole system on your own infrastructure, under your own model key, and your data never touches our servers at all.

Reporting & response

Found a security issue? Report it to security@opennous.cloud or through GitHub Security Advisories — we acknowledge within 72 hours and reward good-faith disclosure. We run a documented incident-response plan and notify affected customers within 72 hours of confirming a personal-data breach.

Documents

Need our SOC 2 details under NDA? Email security@opennous.cloud.