1. Introduction
This Security Policy describes the security measures and operational practices used by Metanoia AS ("Metanoia", "we", "us", or "our") in connection with NET Backup Vault.
NET Backup Vault is a cloud-based platform for backup, restore, monitoring, export, and configuration management of Cisco Meraki environments.
This document is intended to provide transparency regarding the operational and technical security measures currently implemented for NET Backup Vault.
2. Scope
This Security Policy applies to:
- NET Backup Vault platform infrastructure
- Customer account access
- Configuration backup and restore functionality
- Operational monitoring and logging
- Internal administrative access
- Customer support activities related to NET Backup Vault
3. Shared Responsibility
Security is a shared responsibility between Metanoia and the customer.
Metanoia Responsibilities
- Operating NET Backup Vault infrastructure
- Managing platform access controls
- Protecting platform systems and hosted data
- Maintaining operational monitoring and logging
- Applying security updates and patches where appropriate
- Managing secrets and credentials used internally by NET Backup Vault
Customer Responsibilities
- Managing internal user access
- Protecting account credentials
- Managing Cisco Meraki API permissions
- Reviewing restore operations before execution
- Maintaining internal change management procedures
- Maintaining independent backup and disaster recovery strategies where required
- Ensuring lawful and authorised use of NET Backup Vault
4. Hosting and Infrastructure
NET Backup Vault is primarily hosted within the EU/EEA. Infrastructure providers may include Microsoft Azure and Render.com.
Infrastructure design and hosting arrangements may change over time as operational requirements evolve.
5. Access Control
Access to NET Backup Vault systems and customer data is restricted based on operational necessity. Security measures may include:
- Role-based access controls
- Principle of least privilege
- Restricted administrative access
- Authentication controls
- Session management
- Logging of administrative actions
Customers are responsible for managing user access within their own organisation.
6. Authentication and Account Security
NET Backup Vault may support password-based authentication, multi-factor authentication, and role-based permissions.
Customers are responsible for using strong passwords, managing user lifecycle and access permissions, and removing access for unauthorised or former users.
Metanoia reserves the right to suspend accounts or sessions where suspicious or unauthorised activity is detected.
7. Encryption
NET Backup Vault uses encryption measures designed to protect customer data. Security measures may include:
- Encryption in transit using HTTPS/TLS
- Encryption at rest for stored data and credentials
- Secure handling of API credentials and secrets
No encryption or storage mechanism can guarantee absolute security.
8. API Credentials and Secrets
Cisco Meraki API credentials and related secrets are treated as sensitive information. Measures may include encrypted storage, restricted internal access, secrets management systems, and access logging where appropriate.
Customers are responsible for creating and managing API credentials, limiting API permissions appropriately, and revoking credentials when necessary.
9. Backup and Restore Security
NET Backup Vault is designed to support backup and restore operations for Cisco Meraki environments. Restore operations may affect live network configurations.
Security-related measures may include:
- Restore confirmation requirements
- Administrative permissions for restore operations
- Audit logging of restore actions
- Tracking of user actions related to restore functionality
Customers are responsible for reviewing restore actions before execution.
10. Logging and Monitoring
NET Backup Vault may maintain operational and security-related logs. Logs may include authentication activity, user actions, administrative actions, backup and restore activity, API activity, system events, and security-related events.
Logs may be used for security monitoring, operational troubleshooting, incident investigation, abuse prevention, and reliability monitoring.
11. Monitoring and Incident Response
Metanoia monitors NET Backup Vault systems for operational reliability and security-related issues. Where appropriate, Metanoia may investigate suspicious activity, restrict access temporarily, apply mitigation measures, perform emergency maintenance, and notify affected customers where required.
Response actions depend on the nature and severity of the incident.
12. Vulnerability Management
Metanoia may apply security updates and patches, monitor dependencies and infrastructure components, investigate reported vulnerabilities, and prioritise remediation based on operational risk.
Customers may report suspected security issues to [email protected].
13. Internal Access and Confidentiality
Access to customer data is limited to personnel who require access for service operation, support, security investigation, or legal or operational obligations.
Personnel with access to customer data are subject to confidentiality obligations.
14. Subprocessors and Third-Party Services
NET Backup Vault uses third-party providers to support platform operations. Current subprocessors may include Microsoft Azure, Render.com, and Anthropic.
Third-party providers may process limited data necessary to provide hosting, infrastructure, operational tooling, or related functionality. Full details are available on the Subprocessors page.
Metanoia remains responsible for managing subprocessors in accordance with applicable contractual and legal obligations.
15. AI-Related Processing
NET Backup Vault does not use customer configuration backups to train public AI models.
If AI-assisted functionality is introduced in NET Backup Vault, additional disclosures or controls may be provided where appropriate.
16. Data Retention and Deletion
Backup retention depends on the selected customer plan. Unless otherwise stated, the default backup retention period for active customers is 12 months. Data may be retained for up to 30 days after cancellation or termination, after which data may be permanently deleted.
Customers are responsible for exporting required data before termination takes effect.
17. Availability and Operational Continuity
Metanoia aims to provide reliable service availability. Unless otherwise stated in a separate written agreement, paid plans target 99.5% monthly service availability. Availability may be affected by third-party outages, infrastructure failures, internet connectivity issues, or force majeure events.
NET Backup Vault should not be considered a substitute for a complete disaster recovery or business continuity programme.
18. Customer Security Responsibilities
Customers should:
- Use strong authentication practices
- Restrict administrative access
- Review restore actions carefully
- Maintain internal security procedures
- Monitor their own Cisco Meraki environments
- Maintain independent backup and recovery procedures where required
19. Changes to This Security Policy
Metanoia may update this Security Policy from time to time. Material updates may be communicated through NET Backup Vault, by email, or through the Metanoia website.
Continued use of NET Backup Vault after updates become effective constitutes acceptance of the updated Security Policy.
20. Contact Information
Metanoia AS