Security & Compliance

Built to protect rights, financial and personal data.

Noctil processes sensitive catalog, rights, royalty and personally identifiable information. Our security program is built around enterprise expectations — encryption, access control, tenant isolation and privacy by design — and we are actively working toward formal certification.

How we protect your data

Practical controls across data protection, access, operations and privacy.

Data protection & encryption

  • Encryption in transit (TLS) and at rest
  • Secrets and key management via managed cloud services
  • Network isolation and least-privilege service access
  • Regular backups with monitored recovery procedures

Access control & identity

  • Role-based access control (RBAC) and least-privilege permissions
  • Policy-aware access to rights, financial and PII data
  • Identity integration (SSO) support for enterprise deployments
  • Audit trails and operational traceability across workflows

Tenant isolation & operations

  • Logical separation of customer data and workloads
  • Workload isolation for large imports, matching runs and royalty cycles
  • Observability over processing state, failures and exceptions
  • Change management and monitored operational controls

Data privacy & governance

  • Designed around GDPR, California CCPA and India’s DPDP Act
  • Data processed for defined, lawful operational purposes
  • Data subject request handling via privacy@noctil.com
  • Data minimization and retention aligned to operational need

Compliance posture

We are transparent about where we are. Noctil's platform is designed to align with the regulations below, and our SOC 2 controls program is in progress — we have not yet completed a SOC 2 audit. We are happy to share current documentation under NDA.

GDPR EU data protection — program designed to align
CCPA California privacy — program designed to align
DPDP Act India's data protection — program designed to align
SOC 2 Controls program in progress; audit readiness underway

Framework names refer to the standards Noctil's security and privacy program is designed to align with. They do not represent completed third-party certifications unless explicitly stated in writing.

Running an enterprise vendor assessment?

We support security reviews and due-diligence questionnaires for enterprise customers. For security documentation, data processing terms, subprocessor information, or to report a vulnerability, contact security@noctil.com.

Talk to our team