TRUST CENTER
How Nova Silva handles access, evidence and authority
This center summarizes verifiable controls and boundaries in the current architecture. It does not present security certifications or guarantees Nova Silva does not hold.
Data control and separation
Organization context
Operational domains use organization identifiers and access policies to preserve tenant context in queries and sensitive operations.
Authorization-based access
The existence of a record or function does not grant permission by itself. Membership, role and authorization are part of the access boundary.
Evidence and provenance
Provenance
Governed workflows are designed to preserve source, actor, date, scope and the entity relationship of evidence.
Versions and corrections
In critical domains, later corrections should not silently rewrite the evidence or decision that supported an earlier review.
Private documents
Governed document patterns use private storage and controlled references for sensitive evidence.
AI and operational authority
Nova Silva separates explanation or inference from authority to modify data. Sensitive actions must pass through deterministic tools, rules and authorization. When evidence or context is missing, the correct response may be abstention, a documented gap or human review.
A model must not invent an agronomic dose, authorization, geometry, access permission or regulatory conclusion.
Privacy and governance
Purpose and basis
Authorization workflows can record purpose, data categories, applicable basis, consent evidence where relevant, cross-border status, retention reference and privacy-notice version.
Documents and acceptances
Legal-document versions and acceptances are handled as explicit records. Nova Silva should not accept terms or declare authorization on behalf of a customer.
Portability and interoperability
Reporting and evidence workflows are designed to produce reviewable and exportable outputs when the relevant adapter is enabled. Nova Silva is designed to coexist with downstream systems; a specific integration is only presented as available when it exists and has been verified.
What we do not claim
- We do not claim ISO 27001, SOC 2 or another security certification without formal support.
- We do not guarantee zero incidents or perfect availability.
- We do not claim that every module is fully offline.
- We do not publish backup, PITR or retention commitments as SLAs without current supporting documentation.