Security FAQ
Effective 11 August 2026 · Last updated 24 September 2026
What is DeskNova?
DeskNova is a managed, multi-tenant customer support platform — shared inbox, help center, automation, and AI-assisted Nova and Copilot features. It is operated by Techlyft Pty Ltd, incorporated in Australia (ABN 32 635 864 970).
Where is DeskNova hosted?
The managed offering runs on a Hetzner Cloud VPS in Germany (nbg1), with Cloudflare for DNS, tunneling, and object storage (R2) in the European Union, and Litestream replication to R2. Secondary backups are stored in Backblaze B2 in the European Union. See Subprocessors and Security for more detail.
Is customer data encrypted?
In transit: Traffic to DeskNova is served over HTTPS (TLS).
At rest: Specific sensitive configuration values (for example OIDC client secrets and webhook signing secrets) are encrypted at the application layer with AES-256-GCM using an operator-managed key. VPS and object-storage encryption depend on how those services are provisioned by our infrastructure providers.
How are users authenticated?
Workspace access uses password sign-in or optional OIDC single sign-on. Sessions use opaque server-side identifiers with HttpOnly, SameSite=Lax cookies and CSRF protection on state-changing requests. Programmatic access uses personal access tokens scoped to the owning user's permissions. See Security.
What data is required to sign up?
The minimum to create a workspace is a work email address, name, and workspace name. For paid plans, payment card details are processed by Stripe; full card numbers are not stored on DeskNova servers. See Privacy Policy.
What happens to my data if I cancel?
You can export workspace content during your subscription and for up to 30 days after termination. Active systems are purged within 90 days; backups within 365 days. See Data retention and Data return & deletion in the DPA.
What third parties process data?
See our Subprocessors page — including hosting, payments, AI providers when DeskNova funds generations, and PostHog EU analytics.
GDPR
DeskNova processes personal data in accordance with the GDPR and UK GDPR
where applicable — including a controller/processor split, a DPA for workspace contact data,
EU-region analytics (PostHog EU), and AWS Bedrock in eu-central-1 for some
DeskNova-funded AI paths.
Data subject requests: contact [email protected]. We respond within one month where required by law.
Certifications
DeskNova does not currently hold SOC 2, ISO 27001, or similar certifications. See Certifications & SLAs on the Security page.
Reporting a security concern
If you believe you have found a security vulnerability, email [email protected] with enough detail to reproduce the issue. We acknowledge reports within 5 business days and work with you to understand and remediate verified issues. Good-faith security research that respects user data and does not degrade the Service is welcome.