Security at Nous
Nous holds your most sensitive revenue data, so confidentiality, integrity, and availability are built into how the service runs. Identity, storage, and payments are handled by providers independently certified for exactly that job.
Multi-factor authentication
Sign-in runs on Clerk, so every account can be locked down with multi-factor authentication, passkeys, and device checks — not just a password.
Powered by ClerkData encryption
Every request is served over TLS, and data is encrypted at rest. Sensitive credentials like OAuth tokens are additionally encrypted at the application layer with AES-256 before they ever reach the database.
Role-based access control
Access to production and customer data follows least privilege and need-to-know. Every operator has a unique account, access is reviewed regularly, and it's revoked the moment a role changes.
Backups & recovery
The production database is backed up every day, with point-in-time recovery available. We test restores and rebuild from reproducible, container-defined infrastructure.
Powered by SupabasePayment processing
Billing runs entirely on Stripe and Nous never stores your card details. Stripe holds PCI DSS Level 1, the highest certification in payments.
Powered by StripeSOC 2 infrastructure
Nous Cloud is hosted on Supabase, which is SOC 2 Type 2 certified. The controls behind the platform we build on are independently audited every year.
Powered by SupabaseYour data is yours
We use your data only to run the service. We never sell it, and we never train shared or cross-customer models on it. Export any time; delete your workspace and the records are gone.
Open source & self-hosting
The core of Nous is open source. Run the whole system on your own infrastructure, under your own model key, and your data never touches our servers at all.
Reporting & response
Found a security issue? Report it to security@opennous.cloud or through GitHub Security Advisories — we acknowledge within 72 hours and reward good-faith disclosure. We run a documented incident-response plan and notify affected customers within 72 hours of confirming a personal-data breach.
Need our SOC 2 details under NDA? Email security@opennous.cloud.