Nobl.ai

Security Policy

Keeping data safe is one of the things we care about most, whether it is our customers’ data in our services or the data you share with us through our website and accounts. Below is a plain-language summary of how we do it.

Experienced team

Our team combines deep AI/ML engineering with years of running production, enterprise-grade, GDPR-compliant systems on the cloud. Over the past months, we have delivered over 20M recommendations with 99.8% uptime.

World-class infrastructure

We host our services and data on Amazon Web Services (AWS), in the EU by default (Ireland), and in other AWS regions when a customer requires local data residency. Infrastructure is defined as code for consistent, reproducible, auditable deployments, across multiple availability zones for resilience.

Encryption

All data is encrypted at rest (AES-256 via AWS KMS) and in transit (TLS 1.3). Where possible, we avoid storing direct identifiers, and we pseudonymise personal data.

Access control

Access to data is on a strict need-to-know basis. We use role-based access control, an authentication system, password and user-ID policies, network isolation (VPC), least-privilege permissions, and IP allow-listing for administrative access. All access is logged and periodically reviewed. Staff are bound by written confidentiality obligations and receive security-awareness training.

Monitoring & incident response

We continuously monitor system health and security (e.g. AWS CloudWatch, GuardDuty), with automated alerting and threat detection. Incidents follow a defined classification and handling procedure. If a personal-data breach occurs where we act as a processor, we notify the affected customer (the data controller) without undue delay, by phone and email, with the details they need to meet their own obligations. Where we are the controller ourselves (for example, website or account data), we notify the competent supervisory authority, and affected individuals where required, without undue delay.

Resilience & continuity

We maintain backups, a disaster-recovery plan and a business-continuity plan, with data and model artefacts replicated across zones.

Risk management & testing

We run regular vulnerability scanning and penetration testing, keep systems patched, and use anti-virus, firewalls and network-security layers. Application changes go through testing and security controls across development, testing and production before release.

Sub-processors and other providers

Third-party providers (starting with our host, AWS) undergo a security assessment before use and are periodically reviewed. AI features that rely on large-language-model providers (e.g. Anthropic, Google) operate under data-processing agreements that prevent training on customer data, with EU data handling whenever possible. For the personal data we collect as a controller through our website, our providers (including Stripe for payments, SendLayer for email delivery, and Google for analytics and reCAPTCHA) are listed in our Website Privacy Policy.

Ongoing improvement

We review and update these measures regularly in line with the state of the art and any incidents, and we test their effectiveness on a recurring basis.

Scroll to Top