Trust
Security and data controls
This page describes controls currently implemented in Noon. It is a technical overview, not a certification, audit report, or substitute for a written data-processing agreement.
Account security
Noon uses signed, time-limited sessions. Customers can inspect active devices, revoke a single device, or sign out every other device. Password changes, password resets, and verified email changes revoke active sessions; authentication and security events are recorded in the audit trail.
Data controls
Customers can manage profile and workspace settings, export account data, set chat-retention preferences, remove stored items, and request account deletion from the signed-in workspace. Access controls are scoped to the signed-in user and authorized workspace role.
Connected services
Connected-service credentials are encrypted at rest and are not exposed to the model. Noon validates public HTTPS endpoints, blocks private-network targets, limits each connection to owner-approved operations, and requires an explicit approval checkpoint for external writes.
Reliability safeguards
Connector calls use bounded timeouts. Safe read operations receive a bounded retry; repeated failures pause the connection with a circuit breaker. Known-expired OAuth authorization and rejected provider credentials remove the connection from service until its owner reconnects it.
Assurance scope
Noon does not claim a security certification, regulatory attestation, or processor agreement on this page. A complete customer compliance package requires the operating entity, support and incident contacts, data locations, retention commitments, subprocessors, and signed legal terms.