What each framework actually covers, per deployment model
Four ways to run Incident Copilot, seven frameworks customers ask about. Each framework below is broken into what Incident Copilot's architecture actually provides, and what sits outside Noviqent's scope — either a certification that's on our roadmap rather than obtained yet, or a piece of responsibility that stays with you regardless of deployment model. So your own vendor assessment has something concrete to check against.
SaaS
Grafana/Jira/GitHub read, AI reasoning, drafts and tickets
SaaS + cloud APIs
Direct calls from our platform into a reachable cluster you own
SaaS + satellite agent
A small agent inside your own private cluster, orchestrated by us
Fully hosted by you
The whole application, on your own infrastructure, licensed flat
SOC 2
Trust Services Criteria — Security
SaaS
Provided by Incident Copilot
- Role-based access per organisation, enforced centrally by us
- Credentials encrypted at rest or held in your own Vault
- Append-only audit log of every approval and credential change
Outside Noviqent's scope
- SOC 2 is on Noviqent's roadmap — not yet obtained
SaaS + cloud APIs
Provided by Incident Copilot
- Everything the SaaS column covers
- The credential we call your cloud with is scoped to exactly restart/scale, nothing broader
- Every remediation run logged, whether human-approved or policy auto-executed
- The target cluster's own SOC 2 posture stays fully yours to own and evidence
Outside Noviqent's scope
- Same as SaaS — on Noviqent's roadmap
SaaS + satellite agent
Provided by Incident Copilot
- Everything the SaaS column covers
- In-cluster RBAC with no cluster-admin, no exec, no secrets access
- Agent outcomes audited through the exact same path a direct call uses
- Hardening the agent's own host stays fully in your control
Outside Noviqent's scope
- Same as SaaS — on Noviqent's roadmap
Fully hosted by you
Provided by Incident Copilot
- We provide no infrastructure at all in this mode — access control, monitoring, and audit logging are entirely your own SOC 2 scope to run and evidence
ISO 27001
Annex A — Access Control (A.9), Cryptography (A.10), Operations Security (A.12)
SaaS
Provided by Incident Copilot
- Access control per organisation (A.9)
- Encryption in transit and at rest, or credentials never stored at all via Vault (A.10)
- Operational audit trail (A.12)
Outside Noviqent's scope
- ISO 27001 is on Noviqent's roadmap — not yet obtained
SaaS + cloud APIs
Provided by Incident Copilot
- Everything the SaaS column covers
- TLS end-to-end into your cloud for every remediation call
Outside Noviqent's scope
- Same as SaaS — on Noviqent's roadmap
SaaS + satellite agent
Provided by Incident Copilot
- Everything the SaaS column covers
- Outbound-only connectivity — no inbound port opened on your network
Outside Noviqent's scope
- Same as SaaS — on Noviqent's roadmap
Fully hosted by you
Provided by Incident Copilot
- All of Annex A is fully yours to define and run as your own ISMS scope in this mode
UK GDPR
Art. 5 (minimisation) · Art. 28 (processors) · Art. 32 (security) · Art. 44 (transfers)
SaaS
Provided by Incident Copilot
- Noviqent acts as your processor under a Data Processing Agreement
- Full sub-processor register, disclosed and kept current
- Data processed and stored on UK infrastructure Noviqent operates directly
- Which AI provider (if any) receives gathered context is fully disclosed, and it's your organisation's own choice — including a private-hosted endpoint that keeps it off any third party entirely
SaaS + cloud APIs
Provided by Incident Copilot
- Everything the SaaS column covers
- Remediation adds no new personal-data processing beyond what's already disclosed
SaaS + satellite agent
Provided by Incident Copilot
- Everything the SaaS column covers
- Kubernetes credentials and cluster data never leave your own infrastructure
Fully hosted by you
Provided by Incident Copilot
- Strongest option for data residency — no incident data reaches Noviqent at all
- No vendor DPA required, since Noviqent isn't a processor in this mode
- You remain fully your own data controller
DORA
Art. 28–30 — ICT third-party risk (EU/UK financial entities)
SaaS
Provided by Incident Copilot
- A real incident record — timeline, root cause, severity, resolution — for your ICT third-party risk register
Outside Noviqent's scope
- Noviqent's own criticality designation under DORA is for your regulator to assess, not something we self-declare
SaaS + cloud APIs
Provided by Incident Copilot
- Everything the SaaS column covers
- Which remediation actions ran, and under what policy, as evidence
Outside Noviqent's scope
- Same criticality caveat as SaaS
SaaS + satellite agent
Provided by Incident Copilot
- Everything the SaaS column covers
- Added evidence that execution never left your own infrastructure
Outside Noviqent's scope
- Same criticality caveat as SaaS
Fully hosted by you
Provided by Incident Copilot
- No third party in the loop at all — DORA's third-party-provider requirements simply don't apply to this deployment
Cyber Essentials
Boundary firewalls · secure configuration · access control · malware protection · patch management
SaaS
Provided by Incident Copilot
- All five technical control areas, applied to the infrastructure we operate directly
Outside Noviqent's scope
- Cyber Essentials is on Noviqent's roadmap — not yet obtained
SaaS + cloud APIs
Provided by Incident Copilot
- Same as SaaS — this column adds no new infrastructure of ours
Outside Noviqent's scope
- Same as SaaS — on Noviqent's roadmap
SaaS + satellite agent
Provided by Incident Copilot
- Applies to our own infrastructure
- Hardening the agent's own host stays fully in your control
Outside Noviqent's scope
- Same as SaaS — on Noviqent's roadmap
Fully hosted by you
Provided by Incident Copilot
- The entire technical scope is fully yours to run and evidence in this mode
NCSC Cloud Security Principles
Principles 1 & 5 (data protection), 9 (identity & access), 4 (governance)
SaaS
Provided by Incident Copilot
- Data in transit and at rest protection
- Identity and access management per organisation
Outside Noviqent's scope
- A formal NCSC self-assessment is on Noviqent's roadmap — not yet completed
SaaS + cloud APIs
Provided by Incident Copilot
- Everything the SaaS column covers
Outside Noviqent's scope
- Same as SaaS — on Noviqent's roadmap
SaaS + satellite agent
Provided by Incident Copilot
- Everything the SaaS column covers
- Reduced attack surface — outbound-only agent connectivity
Outside Noviqent's scope
- Same as SaaS — on Noviqent's roadmap
Fully hosted by you
Provided by Incident Copilot
- Not meaningfully a "cloud service" in this mode — the principles apply fully to your own infrastructure governance instead
PCI-DSS
Cardholder Data Environment (CDE) scope
SaaS
Provided by Incident Copilot
- Out of scope — this tier only reads via API and drafts a PR/ticket; there is no live write-access into your infrastructure at all
SaaS + cloud APIs
Provided by Incident Copilot
- The remediation credential is scoped to exactly restart/scale — nothing broader — which limits blast radius if the target cluster is CDE-adjacent
Outside Noviqent's scope
- Scope isn't automatically "out" here — it depends on your own network segmentation. If the cluster this reaches also hosts CDE components, that access itself belongs in your own PCI-DSS assessment, not assumed away
SaaS + satellite agent
Provided by Incident Copilot
- In-cluster RBAC has no cluster-admin, no exec, no secrets access — narrower than the direct-API tier
Outside Noviqent's scope
- Same segmentation dependency as the direct-API tier — if the agent's cluster touches your CDE, this access belongs in your own PCI-DSS scope and responsibility matrix
Fully hosted by you
Provided by Incident Copilot
- No third-party service-provider question arises at all — Noviqent has no access to your infrastructure to consider
Questions for your own vendor assessment or a security questionnaire? compliance@noviqent.co.uk. For the underlying data-processing detail, see the Privacy Notice and sub-processor register.