Built with business security in mind.
AI that touches your inbox, your CRM and your customers has to be governed. This page says exactly how we handle that — and what we do not claim.
Authentication
We connect to your systems through each platform's own sign-in and authorisation flow. We do not ask for or store shared account passwords, and access granted to Nolojia can be revoked by you at any time from your own admin console.
Access control
Every integration is granted the narrowest scope its workflow needs — read-only where reading is enough, write access only where the process requires it. Access is reviewed when a workflow changes and removed when an engagement ends.
Encryption
Connections between Nolojia systems and your platforms run over encrypted channels (TLS). Credentials and API keys are held as managed secrets in the hosting environment rather than in application code or repositories.
Controlled integrations
Each connection is deliberate and documented: which system, which scope, which workflow it serves. We do not leave connections in place because they were convenient during a build.
Data protection
We work inside your systems wherever possible rather than copying your data into new places. Where a workflow must store something, we agree what is stored, where it lives and how long it is kept before we build it.
Human oversight
Actions that commit your business stop for a person: pricing, contracts, refunds, first-time external communication, and anything the workflow was not designed to handle. AI drafts; a human releases.
What we do not claim
Nolojia does not currently hold SOC 2, ISO 27001, HIPAA or PCI DSS certification, and we will never imply otherwise on this website. Plenty of companies decorate a security page with badges they have not earned. We would rather you know where we stand.
If your procurement process requires a specific framework, tell us at the first conversation. We will be straight with you about which of your controls we can meet today and which we cannot.
How we use AI on your business.
Security is not only about who can access what. With AI systems it is also about what the system is permitted to decide.
Scoped, not autonomous
Assistants are configured for a defined role with explicit limits. We do not deploy AI that makes unsupervised commercial decisions on your behalf.
Reviewable
Actions taken by a workflow are logged so that when something goes wrong you can see what happened and correct the rule rather than guess.
Honest about failure
AI systems make mistakes. We design for that — approval steps, escalation paths and a person accountable for the outcome — rather than pretending it does not happen.
Your data is yours
We do not sell, share or repurpose your business data. It is used to run the workflows you asked for.
Found a security issue?
If you believe you have found a vulnerability in a Nolojia product or system, tell us before you tell anyone else and we will work with you on it.
See also our Privacy Policy and Terms of Service.
Have security questions before you start?
Ask them now rather than at contract stage. We would rather lose a deal on honesty than win one on a claim we cannot back.
No obligation. We will tell you if automation is not the right answer.