Real-time notification
Hi
I want to know if novu supports real-time notifications and also I want to know if any data is stored when processing and passing through novu engine and whether novu can be configured in a way that can achieve zero customer data on server
please let me know
thanks
11 Replies
Hey @Masoud~ can you share a bit more context as to why?
I am asking so I can propose a solution to the issue on hand.
Hey @Tomer Barnea
for compliance reasons we are looking for zero customer data on servers
for operational reasons we are looking for real time notifications
@Masoud~ thanks for sharing that. So that are a couple of things that could be done. But mostly you should know that, subscriber (ie, user), is being saved, mostly for best practice seperation of concerons in your code base. The other issue is all the audit trail and logs. Now what could be done is, remove those subscibers data in order to clean this. Would you mind sharing which compliance are you going after? Novu is SOC 2 Type II, ISO 27001, and GDPR complaint. Lastly you can deploy Novu internally within your network, so compliance is not an issue.
What would be your first thoughts about this??
@Tomer Barnea thanks for your response
in terms of the normal customer data that we would gather for business operation, like email, payments, etc. it’s not a problem
the problem we have is that we deal with our customer’s customer data
so we need to ascertain nothing of that nature gets stored on our infrastructure and it only passes through securely and encrypted
our aim is to use novu as our notification engine, to transport and deliver notifications to designated channels
but the data that is to be transported and delivered, belongs to our customer’s customers
GDPR, PCI, SOC2 to say the least
NV-3404 - workflow should have the option to disable saving subscriber
As a user I would like to be able to set when a subscriber is added to Novu and when Novu should just keep the data transiant to send a notification. This could be accomplished with a shadown profile that is deleted after the send or more preferably the data just travels with the event. This will effect digest and for the MVP should not allow digest to happen if this is enabled.
Status
Triage
Novu
@Masoud~
Thanks for sharing detailed information.
Above ticket is created in our team linear workspace. This workspace is private to our organization.
Once our team triage this ticket, we will make it public on our github repo as gitub issue
Hey @Masoud~ , given how Novu works today, the best opetion I can offer are, save everything within your network, so your customers or only allowing you the store their users info, or use Novu cloud. I ham happy to talk about PCI DSS, are you storing CC information?
We also added a ticket to allow workflows to run without storing information, although this would impact some capabilities.
@Tomer Barnea we can’t and won’t ask our customer to permit us storing their customers information on our servers as this has major legal implications for both us and our customers as this is literally direct violation of GDPR and other directives
can you elaborate what capabilities would be impacted?
@Masoud~, you just advanced to level 1!
Hey @Masoud~, let's hop on a call together, would be easier. Feel free to grab a slot from my calander https://calendly.com/novuhq/tomer-barnea-30-minutes, or let me know when you have some time and let's do it 😄