What each framework actually covers, per deployment model
Four ways to run Noviqent DevOps, six frameworks customers ask about. Each framework below is broken into what the architecture actually provides, and what sits outside Noviqent's scope — either a certification that's on our roadmap rather than obtained yet, or a piece of responsibility that stays with you regardless of deployment model. So your own vendor assessment has something concrete to check against.
SaaS
Jira/GitHub/GitLab Cloud/Confluence Cloud, AI reasoning, draft PRs
SaaS + cloud APIs
Direct calls from our platform into a reachable self-managed instance you own
SaaS + satellite agent
A small agent inside your own network, for whatever isn't reachable at all
Fully hosted by you
The whole application, on your own infrastructure, licensed flat
SOC 2
Trust Services Criteria — Security
SaaS
Provided by Noviqent DevOps
- Role-based access per organisation, enforced centrally by us
- Credentials encrypted at rest, or held in your own Vault by default
- Append-only audit log of every credential and membership change
Outside Noviqent's scope
- SOC 2 is on Noviqent's roadmap — not yet obtained
SaaS + cloud APIs
Provided by Noviqent DevOps
- Everything the SaaS column covers
- The token we call your self-managed instance with is scoped to exactly what that connector needs — read code, open a pull request — nothing broader
Outside Noviqent's scope
- Same as SaaS — on Noviqent's roadmap
SaaS + satellite agent
Provided by Noviqent DevOps
- Everything the SaaS column covers
- The agent is outbound-only — it polls us, we never open a connection into your network, so there is no inbound attack surface to add to your own SOC 2 scope
- Every job it runs is audited through the exact same path a direct API call uses
Outside Noviqent's scope
- Same as SaaS — on Noviqent's roadmap
Fully hosted by you
Provided by Noviqent DevOps
- We provide no infrastructure at all in this mode — access control, monitoring, and audit logging are entirely your own SOC 2 scope to run and evidence
ISO 27001
Annex A — Access Control (A.9), Cryptography (A.10), Operations Security (A.12)
SaaS
Provided by Noviqent DevOps
- Access control per organisation (A.9)
- Encryption in transit and at rest, or credentials never stored at all via Vault (A.10)
- Operational audit trail (A.12)
Outside Noviqent's scope
- ISO 27001 is on Noviqent's roadmap — not yet obtained
SaaS + cloud APIs
Provided by Noviqent DevOps
- Everything the SaaS column covers
- TLS end-to-end into your self-managed instance
Outside Noviqent's scope
- Same as SaaS — on Noviqent's roadmap
SaaS + satellite agent
Provided by Noviqent DevOps
- Everything the SaaS column covers
- Outbound-only connectivity — no inbound port opened on your network (A.13)
Outside Noviqent's scope
- Same as SaaS — on Noviqent's roadmap
Fully hosted by you
Provided by Noviqent DevOps
- All of Annex A is fully yours to define and run as your own ISMS scope in this mode
UK GDPR
Art. 5 (minimisation) · Art. 28 (processors) · Art. 32 (security) · Art. 44 (transfers)
SaaS
Provided by Noviqent DevOps
- Noviqent acts as your processor under a Data Processing Agreement
- Full sub-processor register, disclosed and kept current
- Data processed and stored on UK infrastructure Noviqent operates directly
- Which AI provider (if any) receives your ticket context and source code is fully disclosed, and it's your organisation's own choice — including a private-hosted endpoint that keeps it off any third party entirely
SaaS + cloud APIs
Provided by Noviqent DevOps
- Everything the SaaS column covers
- No new personal-data processing beyond what's already disclosed
SaaS + satellite agent
Provided by Noviqent DevOps
- Everything the SaaS column covers
- Source code and command output from systems behind your firewall never reach us except through the commands you yourself configured the agent to run
Fully hosted by you
Provided by Noviqent DevOps
- Strongest option for data residency — no ticket or source-code data reaches Noviqent at all
- No vendor DPA required, since Noviqent isn't a processor in this mode
- You remain fully your own data controller
Cyber Essentials
Boundary firewalls · secure configuration · access control · malware protection · patch management
SaaS
Provided by Noviqent DevOps
- All five technical control areas, applied to the infrastructure we operate directly
Outside Noviqent's scope
- Cyber Essentials is on Noviqent's roadmap — not yet obtained
SaaS + cloud APIs
Provided by Noviqent DevOps
- Same as SaaS — this column adds no new infrastructure of ours
Outside Noviqent's scope
- Same as SaaS — on Noviqent's roadmap
SaaS + satellite agent
Provided by Noviqent DevOps
- Applies to our own infrastructure
- Hardening the agent's own host stays fully in your control
Outside Noviqent's scope
- Same as SaaS — on Noviqent's roadmap
Fully hosted by you
Provided by Noviqent DevOps
- The entire technical scope is fully yours to run and evidence in this mode
NCSC Cloud Security Principles
Principles 1 & 5 (data protection), 9 (identity & access), 4 (governance)
SaaS
Provided by Noviqent DevOps
- Data in transit and at rest protection
- Identity and access management per organisation
Outside Noviqent's scope
- A formal NCSC self-assessment is on Noviqent's roadmap — not yet completed
SaaS + cloud APIs
Provided by Noviqent DevOps
- Everything the SaaS column covers
Outside Noviqent's scope
- Same as SaaS — on Noviqent's roadmap
SaaS + satellite agent
Provided by Noviqent DevOps
- Everything the SaaS column covers
- Reduced attack surface — outbound-only agent connectivity
Outside Noviqent's scope
- Same as SaaS — on Noviqent's roadmap
Fully hosted by you
Provided by Noviqent DevOps
- Not meaningfully a "cloud service" in this mode — the principles apply fully to your own infrastructure governance instead
PCI-DSS
Cardholder Data Environment (CDE) scope
SaaS
Provided by Noviqent DevOps
- Out of scope — this product only reads via API and opens a draft PR; there is no live write-access into any payment infrastructure at all
SaaS + cloud APIs
Provided by Noviqent DevOps
- The token we hold is scoped to exactly read/open-PR on the one repository you connected — nothing broader
Outside Noviqent's scope
- Scope isn't automatically "out" here — it depends on your own network segmentation. If the instance this reaches also hosts CDE components, that access itself belongs in your own PCI-DSS assessment, not assumed away
SaaS + satellite agent
Provided by Noviqent DevOps
- The agent only ever runs commands you configured, and only in the environment you named — never production
Outside Noviqent's scope
- Same segmentation dependency as the cloud-APIs tier — if the agent's own network touches your CDE, this belongs in your own PCI-DSS scope
Fully hosted by you
Provided by Noviqent DevOps
- No third-party service-provider question arises at all — Noviqent has no access to your infrastructure to consider
Questions for your own vendor assessment or a security questionnaire? compliance@noviqent.co.uk. For the underlying data-processing detail, see the Privacy Notice and sub-processor register.