Nova Gov Platform GovOS Applications AI Suite Request access
Security · Version 1.1 · 2026-05-19

Security Overview

How Nova Gov protects Philippine LGU data and the operational integrity of the platform. This page is the public-facing summary; CIOs and IT teams can request a detailed Security Whitepaper or schedule a technical review via landon@zentarailabs.com.

Effective date: 2026-05-11  ·  Aligned with: RA 10173 · ISO 27001 control families · OWASP Top 10  ·  Audit: Daily automated · 3rd-party pen test post-pilot
Honesty about where we are: Nova Gov is in active pilot deployment. The controls below are shipped — they exist in production today. ISO 27001 certification, SOC 2 Type II, and third-party penetration tests are post-pilot deliverables (typically completed in the first 12 months of revenue). We will not claim certifications we don't yet hold. We will tell you exactly where we stand.

Current security posture

Live

Encryption in transit

TLS 1.2+ enforced on all public endpoints. HTTP Strict Transport Security with 1-year max-age and includeSubDomains preload.

Live

Encryption at rest

Database storage encrypted via the hosting provider's native AES-256 encryption. Encryption keys managed and rotated by the provider.

Live

Cloudflare Access on admin surfaces

Email one-time PIN gates protected surfaces (e.g., LGU Dashboard, GIS Intelligence Dashboard) at the edge — before any HTML reaches the browser.

Live

Daily secret scanning

gitleaks runs on every commit and a scheduled daily scan checks production repos. Suspected exposures trigger immediate rotation per a written runbook.

Live

Constant-time PIN compare

All shared-secret PIN validations across the backend use a single constant-time helper. Zero raw `!=` PIN compares in the codebase.

Live

Rate limiting

Every authenticated route is throttled (5–60 req/min depending on sensitivity) to deter brute force and accidental denial-of-service patterns.

Pilot deliverable

SOC 2 Type II

Targeted at 12 months post-first-pilot. Audit scope: security, availability, confidentiality. Engaged auditor TBD.

Pilot deliverable

ISO 27001 certification

Targeted at 18 months post-first-pilot. Aligned with control families from Day 1 so the gap analysis is short.

Detailed security documentation is available on request.

Architecture diagrams, data residency specifics, access control implementation, incident response runbook, and secure development practices are provided under NDA to LGU IT teams, CIOs, and procurement officers evaluating Nova Gov.

Request Security Whitepaper →

Responsible disclosure

If you believe you have found a security vulnerability in Nova Gov, please report it privately to landon@zentarailabs.com with the subject line SECURITY. We commit to:

We do not yet operate a paid bug bounty. We will credit reporters publicly with permission.

Compliance alignment

Service availability

The platform is hosted on Cloudflare Pages (frontend) and Railway (backend) — both providers publish their own availability SLAs. For Founding LGU partners, our target uptime is 99.5% measured monthly (excluding scheduled maintenance windows announced at least 72 hours in advance). Specific SLA terms — including credit schedules — are documented in the Founding Partner services agreement.

Security contact

Reporter mailbox
landon@zentarailabs.com · subject SECURITY
Public PGP key
Available on request
Acknowledgement SLA
2 business days
NPC complaints
privacy.gov.ph