Platform
Tenant isolation, and who may do what.
Two different questions get called security in an evaluation. One is whether another customer can reach your data. The other is whether your own people can only do what they are authorised to do. A labeling system has to answer both.
What the architecture guarantees.
A tenant database per customer.
In the hosted service, each customer runs in a logically isolated tenant database: separated at the database level rather than filtered in application code that a bug could bypass. A private-cloud deployment is single-tenant by definition.
Residency has a deployment answer.
Where a hosted service cannot satisfy a data-residency requirement, RONOVA runs in a private cloud without giving up the validated control model.
Single sign-on, or not, per user.
RONOVA authenticates against your existing identity provider over OpenID Connect, Entra ID and Okta among them, or with its own credentials, and which applies is set per user rather than for the whole system. That matters during a rollout, when internal staff are on SSO long before an external site is.
Access control on every action.
Design, review, approve and print are separate permissions, and signing authority is granted rather than assumed. Roles nest, so a senior role inherits what the roles beneath it hold instead of being maintained as a second list. The separation of duties your SOP describes is enforced by the system.
An audit trail you cannot edit.
Every action attributable, timestamped and reconstructable, including access itself, with each sign-in recorded against the device and address it came from, and failed attempts kept with the reason they failed. It is how you answer what happened, not only whether it was allowed.
99.99% uptime.
Innovatum maintains 99.99% uptime. On a labeling system that number is not an abstraction: when labeling is unavailable the line stops, so availability is a production constraint rather than an IT metric.
No installation on the plant floor.
Browser-based printing means no client software to patch across sites, which removes a whole class of exposure that per-site installations create.
Why this page is short.
Most vendor security pages are long and say very little, because it is easy to write a paragraph about taking security seriously and hard to publish a hosting region or a test cadence. This page is the other way round: it states the two things about RONOVA's model that are architectural and verifiable, and it does not fill the remaining space with reassurance.
If you are evaluating RONOVA and your security review needs the rest in writing, ask for it in the first conversation rather than the last. It is a document request, not a negotiation, and the answers exist.
Questions people ask.
Is RONOVA multi-tenant, and is our data mixed with other customers'?
In the hosted service RONOVA is multi-tenant, and each customer runs in a logically isolated tenant database: your records are not interleaved with another customer's in shared tables, because isolation is a property of the data model rather than a filter applied by application code. A private-cloud deployment is single-tenant, so the question does not arise there.
Can we control who is allowed to approve and print labels?
Yes. Role-based access control governs who may design, review, approve and print, and signing authority is an explicit permission rather than an assumption. Every action is recorded in the audit trail, so the enforcement is also evidenced.
Where is RONOVA hosted, and can we choose a region?
RONOVA runs as a hosted cloud service or in a private cloud, so a residency requirement can be met by the deployment model itself. The provider and regions behind the hosted option specifically should come from Innovatum in writing rather than from a marketing summary: ask for it early if EU, Brazilian or Chinese residency is a constraint.
What uptime does RONOVA maintain?
Innovatum maintains 99.99% uptime. Ask for how that is expressed in the subscription agreement (how it is measured, what maintenance is excluded from it, and whether service credits attach) because an operational figure and a contractual service level are different commitments and only one of them is enforceable.
Does Innovatum hold SOC 2 or ISO 27001?
Innovatum's quality system is certified to ISO 9001:2015. Any further independent assurance for RONOVA or its hosting should be requested directly rather than inferred from this page, and if a specific certification is a requirement for your organisation, raise it in the first conversation.
Read next.
Architecture
How RONOVA deploys and fits an existing stack: hosted cloud or private cloud, integrated with ERP, MES and PLM.
Traceability
Full genealogy from incoming material to shipped unit, queryable for the product's regulatory retention period.
Compliance
The regulatory control model.
Validation
Evidence that it does what it claims.
From browser to loading dock.
See how our fully configurable engine adapts to your legacy printing hardware.