Our approach

How NovaLink builds trust, in three stages.

NovaLink's approach to compliance follows three stages. They are sequential and continuous — each one builds on the last.

Stage 01

Published

Complete — 22 documents live

The full documentation set is written and published. Any partner, enterprise customer or regulator can read exactly how the platform and the network are governed, in plain terms.

  • Acceptable use, security, data-handling and operator-protection policies.
  • The corporate structure of The Link Group, set out in full.
  • The public roadmap of what comes next.
Stage 02

Operating

Ongoing — operated daily

These are not documents for a shelf. The controls they describe run continuously, as part of how the platform and network are operated every day.

  • Sanctions screening, security monitoring and incident response across the platform.
  • Abuse reporting and response, with published timeframes, across the platform.
  • Automatic metering and settlement of the bandwidth the network sells.
Stage 03

Independently verified

Underway — on the public roadmap

NovaLink is pursuing independent audits and certifications on the published schedule in the roadmap. Independent verification is how a commitment becomes a proven fact.

  • Independent penetration testing and a no-logs assurance review.
  • SOC 2 and ISO/IEC 27001 certification.
  • Independent verification of the network's revenue reporting, and a public annual transparency report.

Our approach, in one sentence

Publish everything, operate it honestly, and have it verified independently over time.

NovaLink would rather show its work than ask for trust it has not yet earned.

This Transparency Portal is kept current. As each milestone on the roadmap is met, its status here is updated — so what you read is always an accurate picture of where the platform stands.

Transparency roadmap

Where this Transparency Portal is going

This roadmap is specific to the Transparency Portal — the governance, verification, attestation and independent-certification programme that backs the platform and network. It is not the NovaLink product roadmap. Each milestone below is dated and shows its status openly.

  1. Q2 2026In progressStage One

    Foundation

    • Publish the full documentation set and the Corporate Structure & Entity Register.
    • Bring weekly group-wide sanctions / OFAC re-screening into operation.
  2. Q3 2026In progressStage Two

    Operating controls

    • Run the controls daily — sanctions screening, abuse reporting & response, security monitoring and incident response.
    • Roll out hardware-anchored boot attestation on NX1 production units.
  3. Q4 2026PlannedStage Two

    Integrations

    • Bring metering & settlement reporting and the public network statistic online.
    • Complete microVM workload isolation for higher-risk service classes.
    • Publish security.txt, stand up abuse / security intake, and finalise partner-onboarding controls.
  4. 2027PlannedStage Three

    First independent assurance

    • Independent penetration test of the NX1, runtime and platform.
    • Independent no-logs assurance review of the workload runtime.
    • Place cyber-liability and technology errors-and-omissions insurance.
    • Publish the first annual transparency report.
  5. 2027–2028PlannedStage Three

    Independent certification

    • SOC 2 Type I, then Type II over a minimum six-month observation window.
    • ISO/IEC 27001:2022 certification.
    • Ongoing annual independent assurance.