Trust
Security at NOLGIA
Last updated: October 4, 2026
How we protect your data, who processes it, where we are on compliance, and how to report a security problem.
1. Hosting and encryption
In short: NOLGIA runs on Google Cloud in the United States. Data is encrypted in transit and at rest.
- Our servers, database, file storage, backups and logs run on Google Cloud, and we store your data in the United States.
- Data is encrypted in transit and at rest.
- Your files are kept in private storage. The app reaches them through links that expire after a short time.
- Access to production systems is limited to authorized staff.
2. Sign-in and access
In short: Passwords are hashed with argon2id. Keys and tokens are stored only as hashes.
- You can sign in with Google, an email and password, or your organization's single sign-on.
- Passwords are stored only as an argon2id hash, never in a form we can read.
- API keys, access tokens, share links and invite links are stored only as hashes. We show a key once, when you create it.
- You can revoke share links and tokens at any time.
3. Two-step sign-in
In short: Password accounts can add an authenticator app or passkeys, and organizations can require it.
- If you sign in with an email and password, you can turn on two-step sign-in with an authenticator app or a passkey in Settings.
- Turning it on gives you single-use recovery codes. We store them only as hashes, and authenticator secrets only in encrypted form.
- A passkey that verifies you with Face ID, a fingerprint or a device PIN can also sign you in without a password.
- Organizations can require two-step sign-in for members who sign in with a password. Members who sign in with Google, Apple or single sign-on follow that provider's two-step settings, and organizations with SSO enforce it at their identity provider.
- Changing how you sign in asks for your password and second step again, and every change is recorded in your account's security history.
5. Organizations, roles and SSO
In short: Five roles control who can do what. Enterprise adds SAML and OIDC single sign-on and an audit log.
- Organizations have five roles: Owner, Admin, Billing, Member and Viewer.
- Enterprise organizations can require single sign-on with any SAML 2.0 or OIDC identity provider for their verified domain. Other sign-in methods are then refused for that domain.
- Enterprise organizations get an audit log of organization actions, with export.
6. Keeping customers apart
In short: Each account's and organization's data is kept separate from everyone else's.
7. Your content and AI models
In short: We do not train AI models on your content.
8. Deleting your data
In short: Delete your account in Settings. Your data is erased within 30 days, including from backups and logs.
9. Subprocessors and the DPA
In short: We publish every company that processes customer data, and a standard Data Processing Addendum.
10. Compliance
In short: We are preparing for SOC 2 Type II and ISO 27001.
11. Reporting a vulnerability
In short: Found a security problem? Email security@nolgia.ai.
- Test only with accounts you own, and never access, change or delete other people's data.
- Do not run tests that slow down or interrupt the service, and do not use phishing or other social engineering.
- Give us reasonable time to fix the problem before you share it publicly.

