Data protection and encryption
This page describes which data Nova stores and how Nova protects it.
Which data Nova stores
- Identity master data from the HR system and other source systems
- Accounts of the identities in the target systems
- Entitlements and assignments
- Access requests and decisions
- Logs – see Logs
Secrets of target systems
Nova stores the passwords, client secrets and tokens it uses to connect to target systems in encrypted form. Only the operator holds the key; it is not kept in the database.
- Nova checks the key at start-up.
- If the secret of a target system cannot be decrypted, Nova does not use that target system.
- The key can be rotated.
Nova does not store the passwords of accounts in target systems – see Accounts and passwords.
Encrypted connections
- Web interface: over TLS. Encryption is handled by a reverse proxy that the operator places in front of Nova – see Installation.
- Target systems: to directories, Nova transmits passwords only over LDAPS or StartTLS – see Accounts and passwords.
Least privilege
- The database user Nova runs with has no administrative rights in the database.
- “Free Reports” – self-written SQL queries – run read-only and with a restricted database role.
Retention and deletion
Nova permanently deletes identities in the trash once the retention period has expired – see Identities and their status. In doing so, Nova removes the personal data. Log entries are kept for traceability.
Demo and reset functions
Functions that load demo data or reset data cannot run against a production database.
AI
Which data Nova passes to a language model, and whether it leaves the system, depends on the AI mode – see Overview and modes.
Reporting vulnerabilities
A channel for reporting security vulnerabilities is published in a security.txt file.