DeskNova
Omnichannel inboxNovaCopilotKnowledge basePricing
Sign in Start 14-day trial
Omnichannel inboxNovaCopilotKnowledge basePricing
Sign in Start 14-day trial
On this page
  1. Overview
  2. Tenant isolation
  3. Authentication & access control
  4. Sessions & CSRF protection
  5. Activity logs
  6. Sensitive configuration encryption
  7. Internal control-plane boundary
  8. Outbound webhook integrity
  9. Rate limiting
  10. Data storage & uploads
  11. Certifications & SLAs
  12. Reporting a security concern
  13. Contact

Security

Effective 11 August 2026 · Last updated 24 September 2026

Overview

This page describes security controls in the DeskNova platform — both behaviors implemented in the product and the boundaries of what we do not currently offer (for example formal certifications). For common questions, see the Security FAQ.

Tenant isolation

DeskNova is a multi-tenant platform: each customer workspace is a distinct tenant, and core records (conversations, contacts, users, tokens, and similar data) carry a tenant identifier enforced at the data-access layer. Tenant resolution — how a request is mapped to its tenant, for example by subdomain or by the signed-in session — is configurable. A personal access token is pinned to a single tenant at creation and cannot be used to reach a different workspace.

Authentication & access control

Access inside a workspace is governed by roles built from a fixed set of named permissions. Two baseline roles — Admin and Agent — ship by default, and permission changes to a role are recorded in that workspace's activity log.

Workspaces can optionally configure single sign-on via OIDC (Google, Microsoft, or a custom OpenID Connect provider). The provider's client secret is stored encrypted (see Sensitive configuration encryption).

For programmatic access, users can create personal access tokens scoped to a subset of their permissions. Effective permissions are the intersection of token scopes and the owner's current permissions. Token secrets are shown once at creation and stored only as salted hashes. OAuth 2.1 delegated access follows the same seat- and permission-bound model.

Sessions & CSRF protection

Signed-in sessions use opaque, randomly generated identifiers stored server-side with a configurable time-to-live. The session cookie is HttpOnly and SameSite=Lax; Secure is enabled in production. State-changing requests are checked against a separate CSRF token.

Activity logs

Workspaces maintain an internal activity log covering sign-in and sign-out, agent presence changes, password changes, and role/permission changes — each with an actor, target, timestamp, and originating IP address. Logs are available to workspace admins within the product.

Sensitive configuration encryption

Sensitive configuration values — for example OIDC client secrets and webhook signing secrets — are encrypted at the application layer with AES-256-GCM using an operator-managed encryption key. This is field-level protection for those values; whole-database encryption depends on infrastructure-provider settings for the managed VPS and object storage.

Internal control-plane boundary

The product exposes an internal-only HTTP listener for platform control-plane calls, separate from the public application port, authenticated with a shared control-plane token. On the managed offering, this listener is not published to the public internet.

Outbound webhook integrity

Outbound webhook deliveries are signed with HMAC-SHA256 over the request body in the X-DeskNova-Signature header, using a per-webhook secret. Delivery uses a bounded timeout and a delivery queue.

Rate limiting

The platform applies configurable rate limiting to API and AI routes and to the embeddable chat widget to reduce abuse and control load.

Data storage & uploads

On the managed offering, file uploads and attachments are stored in Cloudflare R2 in the European Union. The application database runs on a Hetzner VPS in Germany with Litestream replication to R2 and secondary backups in Backblaze B2 (EU). See Subprocessors.

Certifications & SLAs

The following are not currently offered unless agreed in a separate written contract:

  • Formal certifications (for example SOC 2 or ISO 27001).
  • A published penetration-testing or vulnerability-scanning cadence.
  • A guaranteed uptime or availability SLA (see Terms).
  • Whole-database encryption-at-rest beyond field-level encryption described above.

Breach notification commitments and subprocessors are described in the DPA and Subprocessors pages.

Reporting a security concern

If you believe you've found a security vulnerability in DeskNova, email [email protected] with enough detail to reproduce the issue. We acknowledge reports within 5 business days. Good-faith security research that respects user data and does not degrade the Service is welcome.

Contact

General security questions can be sent to [email protected]. For common questions, see the Security FAQ.

Related documents

This document should be read together with our other legal documents, including:

  • Terms of Service
  • Privacy Policy
  • Data Processing Agreement
  • Cookie Policy
  • AI Policy
  • Subprocessors
  • Security FAQ

Company details

DeskNova is operated by Techlyft Pty Ltd, a company incorporated in Australia (ABN 32 635 864 970), with its registered office at Sydney, NSW, Australia.

Legal and privacy notices: [email protected]

DeskNova

The support desk with Nova for customers and Copilot for your team — both grounded in your docs.

Product

Omnichannel inboxNovaCopilotKnowledge basePricing

Solutions

StartupsE-commerceSaaSEnterprise

Resources

DocsChangelogStatusCommunity

Company

AboutCareersBlogContact
© 2026 Techlyft Pty Ltd. All rights reserved. Legal Privacy Terms Security DPA