Enterprise

Organizational intelligence without giving up control.

For organizations that need governed knowledge, accountable AI, deployment flexibility, and a clear path through security and procurement.

Security model

What you control

  • IntelligenceControl the intelligence layer
  • KnowledgeControl the knowledge
  • AuthorityControl who can do what
  • EvidenceProve what happened
  • DeploymentDeploy deliberately

Intelligence

Control the intelligence layer

Which model answers your organization's questions is a decision you should be able to make — and change.

Bring your own AI provider and keyOn request
Route generation to your own provider account instead of the platform default. Keys are held server-side as secret references — never stored in plaintext, never sent to the browser.
Azure OpenAI and AWS Bedrock routingProduct direction
Run generation inside your own cloud tenant and region. The provider abstraction is in place; these backends are planned, not live.
Private-cloud deploymentOn request
Dedicated and private-cloud patterns are scoped per organization as custom engagements.
Your content is not training dataAvailable now
Content reaches providers through API tiers that are not used to train their public models. Reference photos are never sent to any model at all.

Knowledge

Control the knowledge

Knowledge your experts produced belongs to your organization, and must be portable enough to prove it.

Organization-level isolationAvailable now
Every workspace reaches only its own captures, outputs, knowledge and context packs. Enforced by Row Level Security at the database layer, not by application code alone.
Structured export of approved knowledgeAvailable now
Your organization keeps a portable copy of its governed knowledge base. Export stays available even after an evaluation ends — read-only is not the same as held hostage.
Customer-owned storageOn request
Discussed and scoped per organization for teams that need the store itself under their own control.
Governed lifecycle, not a static archiveAvailable now
Every article carries a status — Current, Needs Review, Stale, Superseded, Archived — and a daily check marks overdue articles stale rather than letting them quietly age.

Authority

Control who can do what

Authority is granted by role and proven by a person — never assumed by the software.

Six-role modelAvailable now
Owner, admin, reviewer, contributor, member, viewer. Capture, edit, approve, export and organization management are separate rights, not one administrator switch.
Human approval is structuralAvailable now
Every AI output stays a draft until a qualified person approves it. There is no configuration that turns this off, because it is what the product is for.
Authenticator-app MFAProduct direction
Time-based one-time passwords from any authenticator app — Google Authenticator, Microsoft Authenticator, 1Password, Authy — with a second enrolled factor as the supported recovery path. Built and merged; not yet confirmed operational on the production authentication project, and organization-wide enforcement is a separate step after that.
SSO and SCIM provisioningProduct direction
Single sign-on and directory-driven provisioning are not built. Organizations that need them should raise it in an evaluation so it can be scoped honestly.

Evidence

Prove what happened

An answer you cannot trace is an answer you cannot defend in a review, an audit, or an incident.

Append-only activity logAvailable now
Captures, draft generation, approvals, governance decisions, file uploads and exports are recorded with actor and time. Owners and admins read their own organization's log.
Chain of custody on evidenceAvailable now
Source files carry their handling history, so a claim can be walked back to the material it came from rather than to a summary of it.
Answers cite approved knowledgeAvailable now
NOVA answers from your approved knowledge and shows what it used. Where the evidence does not support an answer, it says so instead of producing a plausible one.
Governance evidence reportingAvailable now
Approval history and governance decisions assembled for a reviewer who was not in the room when the decision was made.

Deployment

Deploy deliberately

Getting through security review and procurement is part of the product, not an afterthought handed to you in a spreadsheet.

Security review supportAvailable now
A published security model, an attack-surface inventory, and answers to the questionnaire your security team will send.
Data Processing AgreementOn request
A DPA is available on request. We do not represent GDPR or CCPA compliance without independent legal review, and we will not sign a claim we have not verified.
Implementation and governance designOn request
Sales-assisted rollout: identify the knowledge that matters, establish who reviews it, and put NOVA to work where it pays first.
Framework alignmentReadiness — not certified
Controls are mapped to NIST CSF 2.0, OWASP ASVS Level 1, SOC 2 and ISO/IEC 27001. These are readiness baselines that guide the programme — not certifications, and we will not describe them as such.

What we do not claim

Said here, not discovered later

  • We are not SOC 2 audited and not ISO/IEC 27001 certified. Readiness documentation is not a certificate.
  • We do not claim GDPR or CCPA compliance without independent legal review.
  • SSO, SCIM and in-tenant model routing are not built today. They are named here so no one discovers that after signing.
  • DebriefCore does not certify readiness, replace regulatory safety management, or substitute for instructor, mechanic or engineering authority.

For your review

Everything security and procurement will ask for, published.

Enterprise evaluation

Bring the hardest security questionnaire you have.

An enterprise evaluation scopes deployment, AI control, data ownership and the procurement path for your organization — and names plainly what is not built yet.

See plans