NNovGuard
LoginScan your AI
Trust center

Security product. Security posture.

Explicit authorization, least privilege, redaction and hardened runtime boundaries.

Authorized scanning

Target verification is required before red-team testing; private and reserved network targets are rejected to reduce SSRF risk.

Hardened service

The production container runs read-only, drops Linux capabilities, uses no-new-privileges and is exposed only through the reverse proxy.

Session protection

HTTP-only sessions, strict SameSite behavior, secure HTTPS cookies and CSRF checks protect state-changing portal actions.

Secret handling

Security analysis includes secret-pattern detection and redaction before downstream use.

Evidence & audit

Findings, policy decisions and scan reports provide reproducible remediation evidence.

Controlled enforcement

Monitoring is separated from blocking; high-impact actions can require approval or quarantine.