Trust

Security & Data Protection

Security and privacy are important to how NOVA HUB is designed and operated. We use administrative, technical, and organizational safeguards designed to protect user and business information while providing secure access to the platform and its integrations.

Last updated: August 18, 2026

1. Authentication & Account Security

NOVA HUB uses a dedicated platform authentication provider to manage user authentication. NOVA HUB itself does not directly store or validate user passwords. Authentication and session management are handled through the platform's authentication infrastructure.

Users are responsible for protecting their account credentials, using strong passwords where supported, and promptly reporting suspected unauthorized access to info@novabsc.com.

2. Access Controls & Data Isolation

NOVA HUB applies server-enforced authorization rules designed to ensure users can access only the information and functionality permitted for their account, role, and organizational relationship. Access restrictions are enforced at the application and data layer and are not based solely on hiding information in the user interface.

Access controls may include:

  • Role-based access controls
  • Subscription or tier-based permissions where applicable
  • Ownership-based data access
  • Organizational or hierarchy-based access where appropriate
  • Administrator-only controls for privileged functions

Different NOVA HUB features may apply different authorization requirements depending on the sensitivity of the information and the feature's purpose.

3. Data Transmission & Application Secrets

NOVA HUB is delivered over HTTPS. Data transmitted between your browser and NOVA HUB is protected in transit using HTTPS/TLS.

Sensitive application credentials such as OAuth client secrets and server API credentials are kept in server-side environments and are not intentionally embedded in frontend/browser code. Certain third-party integrations may require credentials or authorization tokens, which are restricted through application access controls.

4. Private Documents & Sensitive Files

New sensitive personal and client-related document uploads in NOVA HUB are stored using private-file storage. Access to private documents is subject to authorization controls. Authorized users receive temporary, time-limited access links when viewing or downloading private documents. These temporary links expire rather than functioning as permanent public access links.

Personal Vault documents and applicable FNA/client documents use these private-access mechanisms for new uploads. This description applies to the current architecture for new sensitive uploads and does not mean that every historical document ever uploaded to NOVA HUB has been migrated to private storage.

5. Google Account Integrations

Google integrations are optional. Users choose whether to connect their Google account and authorize the requested permissions through Google's OAuth consent process.

Gmail

NOVA HUB's Gmail integration is designed for sending email on behalf of the connected user when the user initiates or authorizes that functionality. NOVA HUB requests send-only Gmail access for this functionality. NOVA HUB does not request permission to read, search, or modify the user's Gmail inbox.

Google Calendar

NOVA HUB can connect with Google Calendar to support appointment synchronization and calendar availability. Calendar permissions support the calendar functionality authorized by the user. Where external calendar events are used for availability, NOVA HUB is designed to present personal external calendar blocks as "Busy" rather than exposing personal event titles to other users.

Disconnecting Google

Users can disconnect their Google integrations. NOVA HUB's disconnect process requests revocation of the Google authorization and clears stored access/refresh credentials from the applicable integration record.

Additional information is available in the NOVA HUB Privacy Policy.

6. Integrations & Payment Security

NOVA HUB integrates with third-party service providers where necessary to provide certain functionality. Those services operate under their own terms, privacy policies, and security practices.

Payments are processed through Stripe. NOVA HUB does not directly store raw payment-card information submitted through Stripe's payment experience.

Users control optional integrations where applicable. Third-party integrations are subject to their own security, privacy, and availability practices.

7. Monitoring & Responsible Security Practices

NOVA HUB maintains operational logging for certain application and integration activities to support reliability, troubleshooting, and platform operations. Security is an ongoing process, and NOVA HUB may continue to improve its technical and organizational safeguards as the platform evolves.

8. Privacy & User Control

NOVA HUB's security practices work together with its Privacy Policy. Users can manage certain account and integration settings, disconnect optional Google integrations, and request assistance regarding personal information or account data.

For privacy or security questions, contact info@novabsc.com.

9. Responsible Disclosure

If you believe you have identified a potential security vulnerability involving NOVA HUB, please report it privately to info@novabsc.com. Reports should include enough information to understand and reproduce the potential issue.

We ask that researchers avoid:

  • Accessing information that does not belong to them
  • Disrupting NOVA HUB services
  • Destroying or altering data
  • Publicly disclosing a vulnerability before Nova BSC LLC has had a reasonable opportunity to investigate it
Ready to enter the Hub?
Sign in to the NOVA operational app.
Enter the Hub