Security

This page summarises what NovuHub does to protect a workspace and what the operator is responsible for. Report vulnerabilities to the address in /.well-known/security.txt.

Accounts and sessions

Authorisation

Web application protections

Data

Supply chain and process

Operator checklist

  1. Set a unique SECRET_KEY and keep it stable.
  2. Terminate TLS at nginx; keep COOKIE_SECURE=1.
  3. Configure NOVUHUB_SECURITY_CONTACT and a monitored support mailbox.
  4. Turn on offsite backups and the weekly restore test.
  5. Prefer SSO + SCIM for companies with an identity provider.
  6. Keep the server updated (git pull + the upgrade steps) and watch the changelog for new switches.