Security & Trust Center
NobleStark security program, compliance posture, and trust documents.
Current Version: 2.0 • Last Updated: 2026-05-12
This is the current version of our security & trust center. Previous versions are available for reference.
NobleStark builds proprietary datasets, custom benchmarks, and human-expert evaluations for companies building serious AI — from enterprise ML teams and applied-AI startups to leading research labs and hyperscalers. The data we handle — customer model artifacts, expert work product, candidate information — is treated with controls appropriate to a high-trust B2B vendor.
This page documents the controls we operate, the frameworks we align to, and the documents and reports available to customers and prospective customers. We do not claim certifications we do not hold; certifications currently in progress are noted explicitly.
Reach our security team
For vulnerabilities, security questionnaire requests, audit reports under NDA, or customer security reviews: security@noblestark.com
Compliance posture
We align our control program to the NIST Cybersecurity Framework, the SOC 2 Trust Services Criteria, ISO/IEC 27001 control families, and OWASP application-security guidance. We comply with GDPR (as both controller and processor, depending on context) and the CCPA/CPRA.
SOC 2 Type II
PlannedControls aligned to SOC 2 Trust Services Criteria. Formal audit engagement planned; not yet certified.
ISO/IEC 27001
PlannedControls aligned to ISO/IEC 27001 Annex A. Certification engagement on the roadmap; not yet certified.
GDPR (EU/UK)
In effectDPA available on request. EU Standard Contractual Clauses incorporated for cross-border transfers.
CCPA / CPRA
In effectDSAR portal at /dsar. Consumer rights honored within statutory timelines.
HIPAA
Not currentlyWe do not knowingly process PHI. Engagements involving regulated health data require explicit scoping; BAAs available on request.
FedRAMP / IL-class
Not currentlyAvailable under a separately scoped engagement; reach out to discuss federal or defense use cases.
We list certifications only when they are formally held. Frameworks marked "Planned" describe controls we have implemented and aligned to, ahead of a formal audit engagement.
Application security
- Secure SDLC: design review, threat modeling on new services, security review gate before production
- Static analysis (SAST) on every pull request; secrets scanning on every commit
- Software composition analysis (SCA) with daily CVE feeds and SLA-driven remediation
- Mandatory code review by a second engineer; merge protection on main branches
- Periodic third-party penetration testing; remediation tracked to closure
- Web Application Firewall (WAF) and bot mitigation at edge
- Centralized authentication for internal tools (SSO + MFA enforced)
Data security
- Encryption in transit: TLS 1.2+ for all customer and expert-facing traffic; HSTS enforced
- Encryption at rest: AES-256 (cloud-managed KMS) on application databases, object storage, and backups
- Key management: cloud KMS with key rotation, separation of duties, and audit logging on every key operation
- Data classification policy mapping every dataset to handling rules (public, internal, customer-confidential, expert-confidential, regulated)
- Secure deletion: customer data deleted within 30 days of engagement termination unless retention is contractually required
- Encrypted backups with cross-region redundancy; restore tested quarterly
- RTO/RPO targets defined per service tier and verified in periodic disaster-recovery exercises
Infrastructure security
- Primary cloud provider: Google Cloud Platform; production workloads in hardened, segmented projects
- Multi-zone deployment with automated failover for stateful services
- Network segmentation: private subnets for production data stores, no direct public ingress
- WAF, DDoS protection, and rate limiting at the edge
- Intrusion detection on production hosts; centralized log aggregation and alerting
- Container images built from hardened base images; vulnerability-scanned before deploy
- All administrative access via short-lived credentials brokered by a centralized identity provider
Identity & access management
- Single sign-on (SSO) for all internal tools; MFA mandatory and enforced at the IdP layer
- Role-based access control mapped to job function; least-privilege defaults
- Just-in-time elevation for privileged operations with peer approval and full audit trail
- Quarterly access reviews; deprovisioning SLA of 24 hours from termination
- Service-to-service authentication via workload identity, not long-lived secrets
- Privileged session recording for production data-plane access
Endpoint security
- All company-issued laptops are MDM-managed (Jamf / Intune) with enforced full-disk encryption
- EDR (endpoint detection and response) on every device; alerts triaged 24/7 via on-call
- Mandatory screen-lock and idle timeout enforced via MDM
- Patch SLAs by severity: critical within 7 days, high within 30 days, others within 90 days
- Removable media use restricted; only encrypted, MDM-approved devices permitted
- Personal devices excluded from production data access; expert work performed in browser-based tooling we control
Personnel & workforce security
- Background checks on all employees and full-time contractors prior to onboarding (where legally permitted)
- Mandatory confidentiality agreements signed at onboarding
- Annual security and privacy awareness training; phishing simulations quarterly
- Documented separation procedures with same-day deprovisioning of credentials and devices
- Role-specific training: engineering security training for engineers; data-handling training for operations
- Insider-threat program: privileged-access monitoring and anomaly detection
Expert / contractor controls (Hatch)
- NDA at onboarding for every Hatch expert before any project access
- Per-project scoped NDA and IP terms layered on the master contractor agreement
- Customer data accessed only through NobleStark-managed environments; no exfiltration to expert-personal storage
- Expert work product is reviewed before delivery; review trail attached to every item
- Customer model artifacts and prompts are never used to train internal NobleStark models
- Experts cannot identify customers unless customer-side authorization is in place
- Audit logging on expert access to project data; anomaly review weekly
Vendor & subprocessor management
- Subprocessor inventory maintained publicly at /subprocessors
- Vendor risk reviews before onboarding; periodic re-review for critical vendors
- Data processing agreements (DPAs) in place with every subprocessor that handles customer or candidate data
- Critical-vendor contingency planning: documented alternatives for primary cloud, identity, and email providers
Incident response
- 24/7 on-call rotation across engineering and security
- Documented incident response runbook reviewed at least annually and exercised in tabletop drills
- Severity classification (SEV1–SEV4) with defined customer-communication SLAs
- Customer breach notification within 72 hours of confirmation (GDPR-aligned), faster where contractually required
- Post-incident review for every SEV1/SEV2 with corrective actions tracked to closure
- Forensics: evidence-preservation protocol and external IR retainer in place
Business continuity & disaster recovery
- Service-tier-specific RTO and RPO targets, exercised at least annually
- Encrypted backups in geographically separated regions; restore tested quarterly
- Multi-region deployment for production data plane
- Documented BC/DR plan including communications playbook
Privacy program
- GDPR Article 28 processor obligations met; SCCs in place for EU/UK data flows
- CCPA/CPRA compliant; DSAR intake at /dsar
- Retention schedules per data class with automated deletion where feasible
- Data minimization defaults: we only collect what an engagement requires
- Candidate / expert privacy notice published separately at /expert-privacy
- Cookie policy with consent management; see /cookies
Vulnerability disclosure
Responsible disclosure
We welcome reports from security researchers. Email security@noblestark.com with reproduction steps, impact, and your preferred disclosure timeline. We acknowledge within 48 hours, triage within 5 business days, and coordinate public disclosure after a fix ships.
Safe-harbor statement
We will not pursue legal action against researchers who:
- Report vulnerabilities through security@noblestark.com
- Avoid accessing, modifying, or deleting data belonging to others
- Do not perform actions that could harm our services or users
- Allow us reasonable time to remediate before public disclosure
Documents & resources
Reports available under NDA
- SOC 2 readiness report and current control inventory
- Most recent third-party penetration test summary
- Security questionnaire response (SIG-Lite / CAIQ / custom formats)
- Business continuity / disaster recovery plan overview
- Insurance certificates (cyber liability and E&O)
Email security@noblestark.com to request any of the above. We respond within one business day with an NDA and delivery instructions.
Contact
Security issues: security@noblestark.comCustomer security reviews: security@noblestark.comNoble Stark LLC · 131 Continental Dr Suite 305, Newark, DE 19713, US
Last updated: 2026-05-12 · Version 2.0
This Trust Center describes the controls we operate today and is updated as controls evolve. Material changes are noted in the change history at /legal/versions.