What each framework actually covers, per deployment model

Four ways to run Incident Copilot, seven frameworks customers ask about. Each framework below is broken into what Incident Copilot's architecture actually provides, and what sits outside Noviqent's scope — either a certification that's on our roadmap rather than obtained yet, or a piece of responsibility that stays with you regardless of deployment model. So your own vendor assessment has something concrete to check against.

SaaS

Grafana/Jira/GitHub read, AI reasoning, drafts and tickets

SaaS + cloud APIs

Direct calls from our platform into a reachable cluster you own

SaaS + satellite agent

A small agent inside your own private cluster, orchestrated by us

Fully hosted by you

The whole application, on your own infrastructure, licensed flat

SOC 2

Trust Services Criteria — Security

SaaS

Provided by Incident Copilot

  • Role-based access per organisation, enforced centrally by us
  • Credentials encrypted at rest or held in your own Vault
  • Append-only audit log of every approval and credential change

Outside Noviqent's scope

  • SOC 2 is on Noviqent's roadmap — not yet obtained

SaaS + cloud APIs

Provided by Incident Copilot

  • Everything the SaaS column covers
  • The credential we call your cloud with is scoped to exactly restart/scale, nothing broader
  • Every remediation run logged, whether human-approved or policy auto-executed
  • The target cluster's own SOC 2 posture stays fully yours to own and evidence

Outside Noviqent's scope

  • Same as SaaS — on Noviqent's roadmap

SaaS + satellite agent

Provided by Incident Copilot

  • Everything the SaaS column covers
  • In-cluster RBAC with no cluster-admin, no exec, no secrets access
  • Agent outcomes audited through the exact same path a direct call uses
  • Hardening the agent's own host stays fully in your control

Outside Noviqent's scope

  • Same as SaaS — on Noviqent's roadmap

Fully hosted by you

Provided by Incident Copilot

  • We provide no infrastructure at all in this mode — access control, monitoring, and audit logging are entirely your own SOC 2 scope to run and evidence

ISO 27001

Annex A — Access Control (A.9), Cryptography (A.10), Operations Security (A.12)

SaaS

Provided by Incident Copilot

  • Access control per organisation (A.9)
  • Encryption in transit and at rest, or credentials never stored at all via Vault (A.10)
  • Operational audit trail (A.12)

Outside Noviqent's scope

  • ISO 27001 is on Noviqent's roadmap — not yet obtained

SaaS + cloud APIs

Provided by Incident Copilot

  • Everything the SaaS column covers
  • TLS end-to-end into your cloud for every remediation call

Outside Noviqent's scope

  • Same as SaaS — on Noviqent's roadmap

SaaS + satellite agent

Provided by Incident Copilot

  • Everything the SaaS column covers
  • Outbound-only connectivity — no inbound port opened on your network

Outside Noviqent's scope

  • Same as SaaS — on Noviqent's roadmap

Fully hosted by you

Provided by Incident Copilot

  • All of Annex A is fully yours to define and run as your own ISMS scope in this mode

UK GDPR

Art. 5 (minimisation) · Art. 28 (processors) · Art. 32 (security) · Art. 44 (transfers)

SaaS

Provided by Incident Copilot

  • Noviqent acts as your processor under a Data Processing Agreement
  • Full sub-processor register, disclosed and kept current
  • Data processed and stored on UK infrastructure Noviqent operates directly
  • Which AI provider (if any) receives gathered context is fully disclosed, and it's your organisation's own choice — including a private-hosted endpoint that keeps it off any third party entirely

SaaS + cloud APIs

Provided by Incident Copilot

  • Everything the SaaS column covers
  • Remediation adds no new personal-data processing beyond what's already disclosed

SaaS + satellite agent

Provided by Incident Copilot

  • Everything the SaaS column covers
  • Kubernetes credentials and cluster data never leave your own infrastructure

Fully hosted by you

Provided by Incident Copilot

  • Strongest option for data residency — no incident data reaches Noviqent at all
  • No vendor DPA required, since Noviqent isn't a processor in this mode
  • You remain fully your own data controller

DORA

Art. 28–30 — ICT third-party risk (EU/UK financial entities)

SaaS

Provided by Incident Copilot

  • A real incident record — timeline, root cause, severity, resolution — for your ICT third-party risk register

Outside Noviqent's scope

  • Noviqent's own criticality designation under DORA is for your regulator to assess, not something we self-declare

SaaS + cloud APIs

Provided by Incident Copilot

  • Everything the SaaS column covers
  • Which remediation actions ran, and under what policy, as evidence

Outside Noviqent's scope

  • Same criticality caveat as SaaS

SaaS + satellite agent

Provided by Incident Copilot

  • Everything the SaaS column covers
  • Added evidence that execution never left your own infrastructure

Outside Noviqent's scope

  • Same criticality caveat as SaaS

Fully hosted by you

Provided by Incident Copilot

  • No third party in the loop at all — DORA's third-party-provider requirements simply don't apply to this deployment

Cyber Essentials

Boundary firewalls · secure configuration · access control · malware protection · patch management

SaaS

Provided by Incident Copilot

  • All five technical control areas, applied to the infrastructure we operate directly

Outside Noviqent's scope

  • Cyber Essentials is on Noviqent's roadmap — not yet obtained

SaaS + cloud APIs

Provided by Incident Copilot

  • Same as SaaS — this column adds no new infrastructure of ours

Outside Noviqent's scope

  • Same as SaaS — on Noviqent's roadmap

SaaS + satellite agent

Provided by Incident Copilot

  • Applies to our own infrastructure
  • Hardening the agent's own host stays fully in your control

Outside Noviqent's scope

  • Same as SaaS — on Noviqent's roadmap

Fully hosted by you

Provided by Incident Copilot

  • The entire technical scope is fully yours to run and evidence in this mode

NCSC Cloud Security Principles

Principles 1 & 5 (data protection), 9 (identity & access), 4 (governance)

SaaS

Provided by Incident Copilot

  • Data in transit and at rest protection
  • Identity and access management per organisation

Outside Noviqent's scope

  • A formal NCSC self-assessment is on Noviqent's roadmap — not yet completed

SaaS + cloud APIs

Provided by Incident Copilot

  • Everything the SaaS column covers

Outside Noviqent's scope

  • Same as SaaS — on Noviqent's roadmap

SaaS + satellite agent

Provided by Incident Copilot

  • Everything the SaaS column covers
  • Reduced attack surface — outbound-only agent connectivity

Outside Noviqent's scope

  • Same as SaaS — on Noviqent's roadmap

Fully hosted by you

Provided by Incident Copilot

  • Not meaningfully a "cloud service" in this mode — the principles apply fully to your own infrastructure governance instead

PCI-DSS

Cardholder Data Environment (CDE) scope

SaaS

Provided by Incident Copilot

  • Out of scope — this tier only reads via API and drafts a PR/ticket; there is no live write-access into your infrastructure at all

SaaS + cloud APIs

Provided by Incident Copilot

  • The remediation credential is scoped to exactly restart/scale — nothing broader — which limits blast radius if the target cluster is CDE-adjacent

Outside Noviqent's scope

  • Scope isn't automatically "out" here — it depends on your own network segmentation. If the cluster this reaches also hosts CDE components, that access itself belongs in your own PCI-DSS assessment, not assumed away

SaaS + satellite agent

Provided by Incident Copilot

  • In-cluster RBAC has no cluster-admin, no exec, no secrets access — narrower than the direct-API tier

Outside Noviqent's scope

  • Same segmentation dependency as the direct-API tier — if the agent's cluster touches your CDE, this access belongs in your own PCI-DSS scope and responsibility matrix

Fully hosted by you

Provided by Incident Copilot

  • No third-party service-provider question arises at all — Noviqent has no access to your infrastructure to consider

Questions for your own vendor assessment or a security questionnaire? compliance@noviqent.co.uk. For the underlying data-processing detail, see the Privacy Notice and sub-processor register.