Scope
EU, DK-facing service, Polish operator
Version
24 June 2026
Operator
Nova Group Sp. z o.o.
CVR360 applies a security-by-design approach appropriate for a source-backed company information service.
1. Operator and contact
Operator: Nova Group Sp. z o.o., ul. Żurawia 6/12 lok. 745, 00-503 Warszawa, Poland, VAT ID PL7011215529.
Security contact: the security contact form
General contact: the contact form
2. Security scope
Security controls may cover account access, payment flows, source credentials, logs, source documents, imported data, generated reports, AI processing and operational monitoring.
3. Credentials
Production credentials and source API tokens must not be committed or printed. Provider passwords and tokens should be stored in macOS login Keychain according to the project credential policy.
4. Danish source access
Adapters for CVR/Datafordeler, Regnskabsdata and Statstidende remain disabled until required access, contracts or credentials are configured. This reduces accidental calls to sources without approved access.
5. Incident reporting
Suspected vulnerabilities or account issues should be reported to the security contact form with enough detail to investigate.