Security & quality

Controlled, documented, and honestly stated.

Handing over customer conversations or operational data is a risk decision before it is a cost decision. This page sets out how Novatek manages that risk — and states plainly what we do not claim.

Certifications: where we stand. Novatek holds no ISO certification, SOC 2 attestation, HIPAA compliance, PCI DSS compliance or equivalent accreditation. If your procurement requires a certified provider, we are not a fit today and will tell you so on the first call. What follows is the operational control that is genuinely in place — which is a different thing from certification, and is described as such.

What is actually in place.

Operational controls Novatek applies to engagements. They are not a substitute for certification, and are not described as one.

Information security
Workspace, device and network controls appropriate to the sensitivity of the data a team handles, defined per engagement rather than applied as a blanket policy.
Access controls
Least-privilege access provisioned by the client, recorded in an access register, reviewed on an agreed schedule and revoked on the day a person leaves the account.
Quality monitoring
Sampled reviews against a scorecard the client helps define, with calibration sessions between both teams to stop the standard drifting.
SOP governance
Documented procedures with named owners, version history and a defined change process. No undocumented process goes live.
Business continuity
Planned cover for staff absence, connectivity interruption and power interruption, documented per engagement with a defined fallback.
Employee screening & training
Confidentiality obligations, security awareness training and role-specific training completed before any live work.
Data handling
Written rules on what may be accessed, stored, exported, printed or discussed — with the default being that data stays in your systems.
Performance reporting
A fixed reporting cadence against agreed metrics, with access to the underlying data rather than a summary you cannot verify.

Built to hold real documentation.

This page is the foundation of a Trust Centre. As Novatek's governance matures, each of these becomes a downloadable, versioned document rather than a paragraph.

Ask for any of these during evaluation and we will send what exists today and tell you plainly what does not:

  • Information security policy
  • Privacy and data-handling policy
  • Quality assurance framework
  • Business continuity and disaster recovery plan
  • Incident response and notification process
  • Sub-processor and third-party register
  • Employee confidentiality and screening policy
  • Responsible use of AI in client delivery
FAQ

Security questions, answered directly

If the answer you need is not here, ask us directly — you will get a specific answer rather than a brochure.

Novatek makes no ISO certification claim on this website. If and when a certification is held, the standard, the certificate number, the issuing body and the expiry date will be published here and the certificate will be available on request. Where a standard is actively being worked towards, this page will say so and name the stage.

No such claim is made anywhere on this site. GDPR is a regulation rather than a certification, and any engagement involving personal data of EU or UK data subjects is scoped against the client’s own obligations, with the appropriate contractual terms in place.

The preferred model is that it is not stored by Novatek at all — teams work inside your systems, so your data stays in your environment with your audit trail intact. Where a workflow genuinely requires local handling, that is defined, minimised and agreed contractually before it begins.

Access is provisioned by you, scoped to the minimum a role requires, documented in an access register, reviewed on an agreed schedule and revoked the day someone leaves the account. You can audit it at any time.

Incident handling, notification timelines and the point of contact on both sides are agreed contractually before launch. You are told about an incident because it is the process, not because you noticed something.

Next step

Send us your security questionnaire.

We will complete it accurately, including the questions where the answer is “not yet”. You get a clear picture rather than an optimistic one.

Call Book a Call