Data protection & encryption
- Encryption in transit (TLS) and at rest
- Secrets and key management via managed cloud services
- Network isolation and least-privilege service access
- Regular backups with monitored recovery procedures
Noctil processes sensitive catalog, rights, royalty and personally identifiable information. Our security program is built around enterprise expectations — encryption, access control, tenant isolation and privacy by design — and we are actively working toward formal certification.
Practical controls across data protection, access, operations and privacy.
We are transparent about where we are. Noctil's platform is designed to align with the regulations below, and our SOC 2 controls program is in progress — we have not yet completed a SOC 2 audit. We are happy to share current documentation under NDA.
Framework names refer to the standards Noctil's security and privacy program is designed to align with. They do not represent completed third-party certifications unless explicitly stated in writing.
We support security reviews and due-diligence questionnaires for enterprise customers. For security documentation, data processing terms, subprocessor information, or to report a vulnerability, contact security@noctil.com.