What each framework actually covers, per deployment model

Four ways to run Noviqent DevOps, six frameworks customers ask about. Each framework below is broken into what the architecture actually provides, and what sits outside Noviqent's scope — either a certification that's on our roadmap rather than obtained yet, or a piece of responsibility that stays with you regardless of deployment model. So your own vendor assessment has something concrete to check against.

SaaS

Jira/GitHub/GitLab Cloud/Confluence Cloud, AI reasoning, draft PRs

SaaS + cloud APIs

Direct calls from our platform into a reachable self-managed instance you own

SaaS + satellite agent

A small agent inside your own network, for whatever isn't reachable at all

Fully hosted by you

The whole application, on your own infrastructure, licensed flat

SOC 2

Trust Services Criteria — Security

SaaS

Provided by Noviqent DevOps

  • Role-based access per organisation, enforced centrally by us
  • Credentials encrypted at rest, or held in your own Vault by default
  • Append-only audit log of every credential and membership change

Outside Noviqent's scope

  • SOC 2 is on Noviqent's roadmap — not yet obtained

SaaS + cloud APIs

Provided by Noviqent DevOps

  • Everything the SaaS column covers
  • The token we call your self-managed instance with is scoped to exactly what that connector needs — read code, open a pull request — nothing broader

Outside Noviqent's scope

  • Same as SaaS — on Noviqent's roadmap

SaaS + satellite agent

Provided by Noviqent DevOps

  • Everything the SaaS column covers
  • The agent is outbound-only — it polls us, we never open a connection into your network, so there is no inbound attack surface to add to your own SOC 2 scope
  • Every job it runs is audited through the exact same path a direct API call uses

Outside Noviqent's scope

  • Same as SaaS — on Noviqent's roadmap

Fully hosted by you

Provided by Noviqent DevOps

  • We provide no infrastructure at all in this mode — access control, monitoring, and audit logging are entirely your own SOC 2 scope to run and evidence

ISO 27001

Annex A — Access Control (A.9), Cryptography (A.10), Operations Security (A.12)

SaaS

Provided by Noviqent DevOps

  • Access control per organisation (A.9)
  • Encryption in transit and at rest, or credentials never stored at all via Vault (A.10)
  • Operational audit trail (A.12)

Outside Noviqent's scope

  • ISO 27001 is on Noviqent's roadmap — not yet obtained

SaaS + cloud APIs

Provided by Noviqent DevOps

  • Everything the SaaS column covers
  • TLS end-to-end into your self-managed instance

Outside Noviqent's scope

  • Same as SaaS — on Noviqent's roadmap

SaaS + satellite agent

Provided by Noviqent DevOps

  • Everything the SaaS column covers
  • Outbound-only connectivity — no inbound port opened on your network (A.13)

Outside Noviqent's scope

  • Same as SaaS — on Noviqent's roadmap

Fully hosted by you

Provided by Noviqent DevOps

  • All of Annex A is fully yours to define and run as your own ISMS scope in this mode

UK GDPR

Art. 5 (minimisation) · Art. 28 (processors) · Art. 32 (security) · Art. 44 (transfers)

SaaS

Provided by Noviqent DevOps

  • Noviqent acts as your processor under a Data Processing Agreement
  • Full sub-processor register, disclosed and kept current
  • Data processed and stored on UK infrastructure Noviqent operates directly
  • Which AI provider (if any) receives your ticket context and source code is fully disclosed, and it's your organisation's own choice — including a private-hosted endpoint that keeps it off any third party entirely

SaaS + cloud APIs

Provided by Noviqent DevOps

  • Everything the SaaS column covers
  • No new personal-data processing beyond what's already disclosed

SaaS + satellite agent

Provided by Noviqent DevOps

  • Everything the SaaS column covers
  • Source code and command output from systems behind your firewall never reach us except through the commands you yourself configured the agent to run

Fully hosted by you

Provided by Noviqent DevOps

  • Strongest option for data residency — no ticket or source-code data reaches Noviqent at all
  • No vendor DPA required, since Noviqent isn't a processor in this mode
  • You remain fully your own data controller

Cyber Essentials

Boundary firewalls · secure configuration · access control · malware protection · patch management

SaaS

Provided by Noviqent DevOps

  • All five technical control areas, applied to the infrastructure we operate directly

Outside Noviqent's scope

  • Cyber Essentials is on Noviqent's roadmap — not yet obtained

SaaS + cloud APIs

Provided by Noviqent DevOps

  • Same as SaaS — this column adds no new infrastructure of ours

Outside Noviqent's scope

  • Same as SaaS — on Noviqent's roadmap

SaaS + satellite agent

Provided by Noviqent DevOps

  • Applies to our own infrastructure
  • Hardening the agent's own host stays fully in your control

Outside Noviqent's scope

  • Same as SaaS — on Noviqent's roadmap

Fully hosted by you

Provided by Noviqent DevOps

  • The entire technical scope is fully yours to run and evidence in this mode

NCSC Cloud Security Principles

Principles 1 & 5 (data protection), 9 (identity & access), 4 (governance)

SaaS

Provided by Noviqent DevOps

  • Data in transit and at rest protection
  • Identity and access management per organisation

Outside Noviqent's scope

  • A formal NCSC self-assessment is on Noviqent's roadmap — not yet completed

SaaS + cloud APIs

Provided by Noviqent DevOps

  • Everything the SaaS column covers

Outside Noviqent's scope

  • Same as SaaS — on Noviqent's roadmap

SaaS + satellite agent

Provided by Noviqent DevOps

  • Everything the SaaS column covers
  • Reduced attack surface — outbound-only agent connectivity

Outside Noviqent's scope

  • Same as SaaS — on Noviqent's roadmap

Fully hosted by you

Provided by Noviqent DevOps

  • Not meaningfully a "cloud service" in this mode — the principles apply fully to your own infrastructure governance instead

PCI-DSS

Cardholder Data Environment (CDE) scope

SaaS

Provided by Noviqent DevOps

  • Out of scope — this product only reads via API and opens a draft PR; there is no live write-access into any payment infrastructure at all

SaaS + cloud APIs

Provided by Noviqent DevOps

  • The token we hold is scoped to exactly read/open-PR on the one repository you connected — nothing broader

Outside Noviqent's scope

  • Scope isn't automatically "out" here — it depends on your own network segmentation. If the instance this reaches also hosts CDE components, that access itself belongs in your own PCI-DSS assessment, not assumed away

SaaS + satellite agent

Provided by Noviqent DevOps

  • The agent only ever runs commands you configured, and only in the environment you named — never production

Outside Noviqent's scope

  • Same segmentation dependency as the cloud-APIs tier — if the agent's own network touches your CDE, this belongs in your own PCI-DSS scope

Fully hosted by you

Provided by Noviqent DevOps

  • No third-party service-provider question arises at all — Noviqent has no access to your infrastructure to consider

Questions for your own vendor assessment or a security questionnaire? compliance@noviqent.co.uk. For the underlying data-processing detail, see the Privacy Notice and sub-processor register.