HomeCerebroNovaCubeMeridianAboutBlogTerms of ServicePrivacy PolicyRefund Policy
Trust & security

Your data. Your rules.
In plain language.

The questions a finance director or IT manager asks before the CEO signs — answered without jargon. Where something is technical, we say so. Where we have limits, we say that too.

One database per company. Not one table with a “company” column — a separate database, with its own backups.
Isolation you can point at
Managers see what was shared with the company. Private working notes stay private, and every look at them is on the record.
Who sees what
Hosted in Kuala Lumpur, Malaysia. Your data does not leave the country to be stored.
Where it lives
Ten plain answers

What happens to your company's knowledge

Cerebro holds what your people know. NovaCube holds your records. Here is how both are kept, who can see them, and what we will never do with them.

1 — One database per company

Each customer gets its own database. There is no shared table that a missed filter could leak across companies. A test suite that tries to read one company's data as another runs before every release.

2 — Who sees what is enforced, not promised

Every fact is marked private, team, department or company, and can carry a clearance level. The rule is applied in the database query itself — a manager's screen physically cannot fetch a colleague's private note.

3 — Every access is on the record

Each search, read and change is written to a log that can be added to but never edited. It records who, when and which items — not the text of the question. An admin who opens a private note must give a reason, and that reason is logged too.

4 — Stored in Malaysia

Cerebro and NovaCube run on servers in Kuala Lumpur (Shinjiru Technology), on separate machines. Data is encrypted on the way to and from your phone or laptop.

5 — Backed up every night, encrypted first

A copy of every company database is taken nightly, encrypted before it leaves the server, and stored on a second Malaysian server. We have restored from these backups end to end — not just assumed they work.

6 — How the AI is used

To answer a question, the AI model receives the question and the handful of memories needed to answer it — not your whole database. Searching, matching and voice-to-text run on our own servers. NovaDyne never trains any model on your data, and our contract says so.

7 — No passwords to steal

People sign in with a link sent to their work email, or with their Microsoft 365 or Google account. Cerebro stores no passwords. Each phone and laptop is a separate connection you can switch off.

8 — When someone leaves

One click switches off their phone, laptop and AI connections together. What they shared with the company stays; their private notes can be reviewed by an admin, with a logged reason, and consolidated or deleted.

9 — Spending you control

Every company has an AI allowance with a hard ceiling. When it is used up the AI features pause until you top up — searching and saving keep working. There are no surprise bills.

10 — Leaving is easy

Your workspace is one database, so your export is a complete copy of everything — memories, documents, decisions, history. On exit you get the full export and certified deletion within 14 days.

What we will never do

Five things you can hold us to.

These are written into every contract, not just this page.

  • Never train an AI model on your data, or let anyone else.
  • Never sell, share or pool your data with other customers — there is no “anonymised industry benchmark” built from your records.
  • Never read your private notes or your staff's conversations, except by your admin, for a stated reason, on the record.
  • Never hold your data hostage: a complete export is yours on request, and certified deletion follows within 14 days of leaving.
  • Never stay quiet about a security incident: affected customers are told within 72 hours, as Malaysian law requires.
For your IT and finance team

The technical facts, in one table.

Copy this into your vendor checklist. If a row is missing, ask — we would rather answer than let you guess.

TenancyOne PostgreSQL database per customer. No cross-database queries in the application; only the migration runner and the billing meter touch more than one.
Access modelPrivate / team / department / company scopes plus a 0–3 clearance level per item, enforced in SQL. Directors and admins can read shared scopes; nobody can browse another person's private items without a logged reason.
Audit trailAppend-only log per company: actor, timestamp, action, item ids, hashed query. Available to your admin in the app.
HostingShinjiru Technology Sdn Bhd, Kuala Lumpur, Malaysia. Cerebro and NovaCube on separate servers; Cerebro on its own hardware, store and runtime.
EncryptionTLS 1.2+ with HSTS in transit. Bearer tokens stored as SHA-256 hashes; third-party integration tokens encrypted at rest (Fernet). Backups GPG-encrypted before leaving the server.
BackupsNightly, encrypted, copied off-box to a second Malaysian server; restore procedure tested end to end.
AuthenticationMagic link by email, Microsoft 365 (Entra ID) or Google sign-in; OAuth 2.1 with PKCE for AI connectors; per-device tokens with expiry and one-click revocation. No passwords stored.
AI processingAnswers: an AI model provider's business API (currently DeepSeek; Anthropic Claude on request) receives the question plus the retrieved memories. Embeddings (bge-small) and voice-to-text (Whisper) run on our servers. Voice replies, if a person sends a voice note, use Microsoft's speech service and can be switched off. Dedicated or on-premises deployment with a model of your choice is available.
Rate limits & capsPer-IP and per-token rate limits on every door; per-company AI allowance with a hard ceiling; per-company document quota.
Data residency & lawData stored in Malaysia. NovaDyne Sdn Bhd acts as data processor under the Personal Data Protection Act 2010; governing law Malaysia; a data processing agreement is available.
Export & deletionFull database export on request; certified deletion within 14 days of contract end.
Incident notificationAffected customers informed within 72 hours of confirming a breach.
CertificationsNone yet — Cerebro launched in 2026. We publish this page instead of a badge, and will update it when an audit is complete.
Proof, not promises

How a pilot earns its keep.

Every NovaCube + Cerebro pilot runs 60 days against four numbers agreed at kick-off. At day 45 both sides sign one scorecard. Case studies will appear here as pilots complete, with each customer's permission.

Real documents produced with AI

Quotations, invoices, reports and messages produced with the AI's help during the pilot — counted, not estimated. Default target: 20.

People actually using it

The share of pilot users active every week, from the system's own logs. Default target: 70%.

Hours given back

Hours per person per week saved, assessed by your sponsor, not by us. Default target: 6.

Knowledge captured and recalled

Facts, decisions and procedures stored in Cerebro, and recalls your people rated useful. Default targets: 100 captured, 10 useful recalls.

Three of four is a pass. The pilot fee is credited in full against the first year if you continue. The first pilots started in September 2026; when they complete we will publish their scorecards here, numbers first.

FAQ

The questions we get asked

Only when you ask us to help with a problem, and then under your instruction. Day to day, nobody at NovaDyne looks inside a customer's workspace. Every access — ours included — lands in your audit log.
It is stored and backed up in Malaysia. When the AI answers a question, the question and the few memories needed for the answer are sent to the AI model provider for processing and are not stored there for training. If your policy requires that no prompt leaves your control, we can run your workspace on a dedicated server with a model you approve, including fully on your premises.
Your company is the data user; NovaDyne is the data processor. We process personal data only on your instructions, keep it in Malaysia, protect it as described on this page, and delete it when you leave. A data processing agreement is part of the contract on request.
No. Managers see knowledge that was shared with the team or company, the decision ledger and the contradiction radar — not private notes and not conversations. An admin can open a private note only with a stated reason, which is logged where staff can see it.
Your data is in one database you can export at any time, in a standard format (PostgreSQL). Cerebro's deployment is a standard Docker Compose stack we can hand over to run yourselves or with another provider.
Not yet. Cerebro launched in 2026. Rather than wait for a badge, we publish exactly what we do on this page and answer any vendor questionnaire in writing. We will update this page when an external audit is complete.
Each company has an AI allowance with a hard ceiling. Usage is metered per call and visible to your admin. When the allowance is spent the AI features pause until you decide to top up; searching and saving keep working. The same protection guards our public demo.
Still have a question?

Send us your
vendor checklist.

We answer security questionnaires in writing, in plain language, usually within two working days — and we will tell you where the honest answer is “not yet”.