Security and data
Last updated 16 August 2026
Noema is pre-launch. No customer business data is processed, no system is connected to anything, and there is no product to secure yet. This page says what is true today and what we are committing to before any customer data is touched.
This website today
The site is a set of static files served over HTTPS. It runs no database, stores nothing about you, and sets no cookies of its own. There is no analytics, no advertising and no tracking on any page.
Form submissions go to Formspree and demo bookings to Calendly, and both reach us as email. The assistant is answered by a small endpoint we run; the API key it uses is held server-side and never reaches your browser, conversations are not stored, and message length, conversation length and request rate are all capped.
What Noema will connect to
The integrations described on the home page are in build. Nothing is connected to any live business system today, and the figures shown in the product panels are illustrative examples rather than real data from anyone.
What we will commit to before any customer data
Read-only access wherever the work allows it, and a person approving anything that leaves the business. Customer data held in the United Kingdom or the European Economic Area. Customer data never used to train models. Deletion on request, and export of what we hold. A written data processing agreement, and a published list of the suppliers involved, before any customer is onboarded.
These are commitments about how Noema will be built, not a description of controls already in place or of any certification held. We hold no security certification today and do not claim one.
Reporting something
If you find a security problem with this site or the assistant, email sachu@noemabrain.com with enough detail to reproduce it. We will confirm we have received it and tell you what we have done.