Trust

Security at NOLGIA

Last updated: October 4, 2026

How we protect your data, who processes it, where we are on compliance, and how to report a security problem.

1. Hosting and encryption

In short: NOLGIA runs on Google Cloud in the United States. Data is encrypted in transit and at rest.

  • Our servers, database, file storage, backups and logs run on Google Cloud, and we store your data in the United States.
  • Data is encrypted in transit and at rest.
  • Your files are kept in private storage. The app reaches them through links that expire after a short time.
  • Access to production systems is limited to authorized staff.

2. Sign-in and access

In short: Passwords are hashed with argon2id. Keys and tokens are stored only as hashes.

  • You can sign in with Google, an email and password, or your organization's single sign-on.
  • Passwords are stored only as an argon2id hash, never in a form we can read.
  • API keys, access tokens, share links and invite links are stored only as hashes. We show a key once, when you create it.
  • You can revoke share links and tokens at any time.

3. Two-step sign-in

In short: Password accounts can add an authenticator app or passkeys, and organizations can require it.

  • If you sign in with an email and password, you can turn on two-step sign-in with an authenticator app or a passkey in Settings.
  • Turning it on gives you single-use recovery codes. We store them only as hashes, and authenticator secrets only in encrypted form.
  • A passkey that verifies you with Face ID, a fingerprint or a device PIN can also sign you in without a password.
  • Organizations can require two-step sign-in for members who sign in with a password. Members who sign in with Google, Apple or single sign-on follow that provider's two-step settings, and organizations with SSO enforce it at their identity provider.
  • Changing how you sign in asks for your password and second step again, and every change is recorded in your account's security history.

4. Share links

In short: Share links can carry a password, turn downloads off and expire on a schedule. Organization admins set the rules.

  • A share link can expire after 1, 7 or 30 days, or never. Links expire after 30 days unless you choose otherwise.
  • A share link can carry a password. Viewers type it before the media opens, and we store it only as an argon2id hash.
  • A share link can be view only, with downloads turned off.
  • You can revoke any share link from the item's share menu or from your share links page.
  • Organization admins can turn public share links off for the whole organization, which also stops existing links, or require a password and a maximum lifetime on new links.

5. Organizations, roles and SSO

In short: Five roles control who can do what. Enterprise adds SAML and OIDC single sign-on and an audit log.

  • Organizations have five roles: Owner, Admin, Billing, Member and Viewer.
  • Enterprise organizations can require single sign-on with any SAML 2.0 or OIDC identity provider for their verified domain. Other sign-in methods are then refused for that domain.
  • Enterprise organizations get an audit log of organization actions, with export.
See Enterprise for details.

6. Keeping customers apart

In short: Each account's and organization's data is kept separate from everyone else's.

Every piece of data belongs to an account or an organization, and every request is checked against that owner before anything is returned.
Each NOLGIA Agent runs in its own workspace, separate from other customers' agents.

7. Your content and AI models

In short: We do not train AI models on your content.

We do not train AI models on your content. Some providers reserve rights, under their own terms, to use data they receive to improve their models. We opt out where a provider offers it, and our Subprocessors page marks those providers.
Model providers receive only what is needed for the models you use, and only when you use them.

8. Deleting your data

In short: Delete your account in Settings. Your data is erased within 30 days, including from backups and logs.

You can delete items, chats and your whole account yourself. When you delete your account, it stays locked for 7 days in case you change your mind, then we permanently delete your Library, Characters, projects, NOLGIA Agent chats and workspace, sign-in credentials, tokens and keys. Deleted data leaves our backups and logs within 30 days of your request. We keep only anonymized records we need for tax and accounting. The Privacy Policy has the full schedule.

9. Subprocessors and the DPA

In short: We publish every company that processes customer data, and a standard Data Processing Addendum.

Our Subprocessors page lists every company that processes customer data for us, what each receives and where. We post a new principal subprocessor there at least 15 days before it starts.
Our Data Processing Addendum covers personal data we process for business customers, including breach notification and the Standard Contractual Clauses for international transfers.

10. Compliance

In short: We are preparing for SOC 2 Type II and ISO 27001.

We are preparing for SOC 2 Type II and ISO 27001. Ask us for our security questionnaire answers at contact@nolgia.ai.

11. Reporting a vulnerability

In short: Found a security problem? Email security@nolgia.ai.

Email security@nolgia.ai with a description of the problem, the steps to reproduce it, and what an attacker could do with it. We will confirm we received your report and keep you updated while we fix it.
  • Test only with accounts you own, and never access, change or delete other people's data.
  • Do not run tests that slow down or interrupt the service, and do not use phishing or other social engineering.
  • Give us reasonable time to fix the problem before you share it publicly.
Our security.txt carries the same contact. If a breach affects your personal data, we notify you and the authorities as the law requires.