PCI DSS Level 1. EMV certified. SOC 2 Type II in progress. Penetration tested by independent third parties. Built on infrastructure that meets enterprise restaurant standards from day one.
The highest level of payment card industry compliance. Required for any platform processing more than 6 million transactions annually.
EMV-certified payment acceptance across all Nova hardware. Tap-to-pay, chip, contactless, and mobile wallet supported.
Independent attestation of Nova's security, availability, processing integrity, confidentiality, and privacy controls. Report available under NDA.
TLS 1.3 in transit. AES-256 at rest. End-to-end encryption on payment flows. Hardware security modules for key management.
Role-based access at every layer. SSO and SAML support for enterprise customers. Multi-factor authentication required for all admin access.
Per-tenant network segmentation. Restaurant data isolated by brand. Zero-trust architecture for service-to-service communication.
Quarterly third-party penetration tests. Continuous vulnerability scanning. Public bug bounty program for security researchers.
24/7 SIEM monitoring. Anomaly detection on payment flows. All admin actions logged and retained per compliance requirements.
Documented incident response plan. Tested quarterly. Customer notification SLAs in your MSA. Status page with real-time incident transparency.
Nova provides every standard procurement artifact you'd ask for from day one. Most enterprise security reviews close in days, not months.