A trust company has to go first.
We hold ourselves to the bar we help you meet. Here's exactly how NobleCloak handles your data, your access, and your evidence.
How we handle your data.
Your data is never used to train
No model trains on your data; no retention beyond what you choose. Plain terms, not buried in a DPA.
Isolation, your choice
Shared, dedicated tenant, or entirely inside your own cloud. Per-org isolation is the floor, not the upsell.
Read-only means read-only
The Discover scan runs on read-only access — it can see, it can never act. Connecting an AI to govern it is a separate, larger consent you grant knowingly.
We audit ourselves
Every scan, every operator action, every export writes to a tamper-resistant log. The audit tool's own actions are audited.
SOC 2 — honest status
We do not hold a SOC 2 report and our audit program has not started. When it does, we'll say so with dates. Our full claim set — including what we can't yet claim — is published at trust.noblecloak.com.
Compliance posture
Frameworks we map to (Interagency 2023-17, NIST AI RMF) and what's in progress vs. complete.
Found something? We want to hear from you.
Reach our security team at security@noblecloak.com.