What is in place, and what is not yet.
The controls we run, where your data lives, who processes it and our compliance status. No borrowed certificates and no badges for audits that have not happened.
Last updated 4 October 2026
Compliance status
Novo Lab has had no SOC 2 audit and holds no ISO 27001 certificate, and it does not display anyone else’s. Its servers and encrypted backups are in Germany; model inference runs with providers in the United States, without a zero-retention arrangement yet. Every AI-generated answer is marked and recorded in a tamper-evident event log kept for 365 days, and neither that log nor the access log holds question or answer text. Novo Lab is not placed on the market as a medical device.
- SOC 2
- No audit has taken place and no Type I or Type II report exists. The controls on this page are designed against the Trust Services Criteria, which is a design commitment and not a certification.
- ISO 27001
- Not certified. Our hosting provider's data centres are certified, and that covers its buildings and hardware, not our application or our processes. We do not present it as ours.
- GDPR
- The technical measures below are in place and every category of data has a retention period. Our records of processing and the processor contracts with every provider are still being completed, and not all of them are in place yet.
- Medical device
- Novo Lab is not placed on the market as a medical device and carries no CE mark. Its intended purpose is evidence retrieval and appraisal for licensed professionals, not diagnosis or treatment of an individual patient. A feature that stated an individual-patient purpose would be assessed under the MDR, and the conformity route completed, before that claim was made.
- EU AI Act
- Every AI-generated answer is marked as such, and every marked answer is recorded in an event log with tamper evidence. The system is not high-risk today. The section on AI transparency below sets out what is recorded.
- What you won’t see here
- Logos of audits we have not passed, certificates that belong to our suppliers, or a seal that says “compliant” without saying with what. When an audit happens, this page will name the auditor, the scope and the period.
Security controls in place
- Encrypted transport: TLS 1.2 or higher, with HSTS for a year across subdomains. Every response carries a content security policy, nosniff and a denied frame ancestor, and a test against the live site fails the release if one goes missing.
- One way in: the servers accept web traffic only from our edge network. A direct request to the origin is refused at the firewall.
- Credentials stored as hashes: passwords with Argon2id; API keys, session tokens, reset tokens and the app’s sign-in codes only as SHA-256 hashes. A copy of the database holds no usable credential.
- Tenant separation: every query, key and record is scoped to the organisation it belongs to, and the scope is enforced in the database query, not only in the interface.
- Metadata-only logging: a request leaves a timestamp, the templated route, the status, the latency and hashed identifiers. Question text, answer text and request bodies are never written to a log.
- Sessions that end: portal and admin sessions close after 30 minutes idle and 8 hours after sign-in, and every state-changing call carries a CSRF token bound to the session.
The security page explains each control in more detail, and how to report a vulnerability to us.
Where data is stored
- Live data
- The application, the engine database, the iOS app’s backend database and the search index run on servers in Germany.
- Backups
- Both databases are backed up every night. Each dump is encrypted with AES-256 before it leaves the server and kept for 14 days with a second storage provider, in its Frankfurt region in Germany.
- Restore tests
- On the first of every month the latest backup of each database is restored into a scratch database and checked against table and row counts. A failed check raises an alert.
- Search index
- Not backed up, on purpose. It is built from published literature and can be rebuilt from the database, so it holds nothing that exists only there.
- Model inference
- Not in the Union yet. Generation and embeddings are processed by model providers in the United States, as described under subprocessors.
Subprocessors
The providers that process data for us, by what they do and where. The list naming each company is sent on request and attached to every data processing agreement.
- Hosting
- Servers in Germany for the application, both databases and the search index.
- Backup storage
- A second provider, in its Frankfurt region, that only ever receives encrypted dumps.
- Edge network
- DNS, TLS termination and protection against attacks for every request, plus the human check on the contact form. It runs on a global network, so a request is first handled near the visitor.
- Model providers
- Two providers in the United States, called over their standard APIs, write the answers and compute the embeddings. A question and the evidence retrieved for it are sent to them. Under their commercial API terms inputs are not used to train their models, but they may be kept for a limited time for abuse monitoring. No zero-retention arrangement is in place. European endpoints with zero retention are planned, not live.
- Email delivery
- A delivery provider in the United States sends the app’s sign-in codes, portal mail and contact form messages on to our inbox.
- Inbox
- Our mailbox, where your messages to us are read and answered, is hosted by Google.
- Website analytics
- Google Analytics, on this website only, without cookies until you accept them. Never in the portal, the API or the app.
A contract under Article 28 GDPR is being concluded with each of them and not every one is in place yet. For the providers in the United States, the safeguards for the transfer under Chapter V GDPR are being put in place with those contracts.
AI transparency
- Marking, Article 50
- Every response that carries generated text says so: an ai_generated field in the body and an X-AI-Generated header on the response, so the marking is machine-readable as well as visible.
- Event log, Article 12
- Every marked response adds one row to an append-only log: the time, the templated route, the organisation, a hash of the key, the model, the prompt and software versions, the ids of the sources cited, whether the engine abstained and the latency. Never the question or the answer.
- Tamper evidence
- Since engine version 0.12.0 every row carries a SHA-256 hash chained to the row before it, computed in the database as the row is written, and the head of the chain is anchored once a day. Changing or removing a row breaks the chain, and a verification run reports the first broken link. This is tamper evidence, not tamper prevention: someone with full database rights could still alter the table, and the daily anchors are what would show it.
- How long
- 365 days, then deleted by the daily retention job. The configuration cannot go below 180 days.
- Risk class
- Not high-risk under the AI Act today: no safety component of a regulated product and no Annex III use. The log is kept anyway, because it is what makes an answer traceable.
How long data is kept
- API access log
- 90 days. A retention job inside the engine’s worker deletes older rows every day, as of engine version 0.12.0.
- AI event log
- 365 days, deleted by the same daily job.
- Citation checks
- The text of a checked claim is kept 45 days for human review, the verdict without it 365 days. Both are removed by the same daily job.
- A deleted app account
- Threads, messages and settings are removed from the live service within 25 hours: an hourly purge runs once a 24-hour grace period ends. If the engine cannot be reached to retire the account’s access key, the account record waits until it can; the threads and messages do not wait.
- Backups
- 14 days, so deleted data has aged out of every backup within 14 days of leaving the live service.
The privacy policy lists every other category of data, including portal accounts, contact messages and analytics, with its retention period and legal basis.
Questions
Is Novo Lab SOC 2 or ISO 27001 certified?
No. Novo Lab has had no SOC 2 audit and holds no ISO 27001 certificate. Its controls are designed against the SOC 2 Trust Services Criteria, and its trust center lists the controls that are actually in place.
Where does Novo Lab store data?
On servers in Germany. Encrypted nightly backups are kept for 14 days with a second provider in Frankfurt, Germany, and restored as a test every month. Model inference is the exception: it runs with providers in the United States.
Are questions sent to Novo Lab used to train AI models?
Under the model providers’ commercial API terms, inputs are not used to train their models. They may be kept for a limited time for abuse monitoring, because no zero-retention arrangement is in place yet. Novo Lab never writes question or answer text to its own logs.
Is Novo Lab a medical device?
No. Novo Lab is an evidence retrieval and grading tool for licensed healthcare professionals. It is not placed on the market as a medical device, carries no CE mark and does not diagnose, recommend treatment for an individual patient or decide dosing.
How does Novo Lab meet the EU AI Act?
Every AI-generated answer is marked in the response body and a response header (Article 50), and every marked answer is recorded in an append-only event log kept for 365 days, with a SHA-256 hash chain that makes a changed or removed row detectable. The system is not high-risk under the Act today.
How long does Novo Lab keep logs?
The API access log is kept 90 days and the AI event log 365 days. A job in the engine deletes older rows every day. Neither log holds question or answer text.