noctara . trust
back

trust.

the documents you need to sign before the architecture enters your room. all three are drafted, formatted, and downloadable. counsel review is recommended before execution.

artifacts

MSA . PILOT LIGHT

Master Services Agreement.

Covers fixed-scope pilot engagement (up to 5 participants, 14 days, $1,300 one-time). Includes scope, fees, IP, liability, termination.
4 pages . pdf . 70kb
download MSA
DPA

Data Processing Addendum.

Governs personal-data processing under the MSA. GDPR/UK-GDPR/CCPA-shaped. Defines controller/processor, sub-processors, retention, deletion, breach notice.
4 pages . pdf . 96kb
download DPA
SECURITY

Security Posture.

One-pager. Architecture overview, encryption, access controls, audit logging, sub-processor list, incident response. The hub-and-spoke privacy model in plain language.
4 pages . pdf . 115kb
download Security
all three documents are operational drafts ready for counsel review on your side. we have not yet completed a third-party SOC 2 audit. we are willing to scope one as a closing condition for engagements at the enterprise tier ($130k+/year). until then the security posture document is the operational truth.

sub-processors

the third parties that process customer or participant data on our behalf. we provide thirty days written notice before adding a new sub-processor.

rolevendorregion
databaseSupabaseUS-East
hostingVercelUS-East
authenticationClerkUS-East
paymentsStripeUS
transactional emailResendUS
compression engineAnthropicUS
file storageSupabase StorageUS-East

what the architecture refuses

we do not sell your data. not to advertisers. not to insurers. not to data brokers. not to governments. not to the highest bidder dressed as a partner. we do not run third-party trackers (no facebook pixel, no standard google analytics) on the consumer surface. we do not train models on private participant text without explicit consent. these are not features. these are refusals written into the architecture.

privacy

the consumer-facing privacy policy is at /privacy. it describes what we collect, what we never collect, and how to take it all back.

incident response

in the event of a confirmed security incident affecting customer or participant data, we notify the customer primary contact within seventy-two (72) hours of confirmation, in writing, with a summary of scope, affected data, mitigation, and timeline. the full incident response procedure is in the security posture document above.

questions

commercial or security questions during evaluation: calkire@noctaracorp.com.

privacy or data-rights requests: her@noctaracorp.com.

noctara, inc. is the operating subsidiary of pupul, inc. marietta, ohio.
all documents above are versioned. material changes will be announced.
last refreshed 2026-05-16.