TRUST & SAFETY
Novauth is built on enterprise-grade infrastructure with security at every layer.
Our services run on ISO 27001-compliant infrastructure hosted within the European Union. All servers are protected by firewalls, intrusion detection systems, and continuous monitoring. We perform regular security audits and penetration tests.
All data in transit is encrypted using TLS 1.3. Sensitive data at rest is encrypted using AES-256. API keys and credentials are hashed using industry-standard algorithms and never stored in plaintext.
Access to the Novauth API requires API key authentication. We support IP allowlisting, rate limiting, and webhook signature verification to protect your integration. All API activity is logged and available in your dashboard.
We enforce two-factor authentication (2FA) for all accounts. Session tokens are short-lived and automatically rotated. Failed login attempts are rate-limited and monitored for suspicious activity.
Novauth connects directly to tier-1 carrier networks via secured SS7 and SIP connections. Our Verify Call service is inherently resistant to SIM-swap and OTP interception attacks because no SMS code is transmitted.
Novauth operates in compliance with GDPR, ePrivacy Directive, and applicable telecom regulations. We maintain data processing agreements (DPAs) with all sub-processors and carrier partners.
If you discover a security vulnerability, please report it responsibly to info@betatel.com. We commit to acknowledging reports within 48 hours and resolving critical issues within 7 days.