NobleCloak
Trust & Security

A trust company has to go first.

We hold ourselves to the bar we help you meet. Here's exactly how NobleCloak handles your data, your access, and your evidence.

How we handle your data.

Your data is never used to train

No model trains on your data; no retention beyond what you choose. Plain terms, not buried in a DPA.

Isolation, your choice

Shared, dedicated tenant, or entirely inside your own cloud. Per-org isolation is the floor, not the upsell.

Read-only means read-only

The Discover scan runs on read-only access — it can see, it can never act. Connecting an AI to govern it is a separate, larger consent you grant knowingly.

We audit ourselves

Every scan, every operator action, every export writes to a tamper-resistant log. The audit tool's own actions are audited.

SOC 2 — honest status

We do not hold a SOC 2 report and our audit program has not started. When it does, we'll say so with dates. Our full claim set — including what we can't yet claim — is published at trust.noblecloak.com.

Compliance posture

Frameworks we map to (Interagency 2023-17, NIST AI RMF) and what's in progress vs. complete.

Responsible disclosure

Found something? We want to hear from you.

Reach our security team at security@noblecloak.com.