Security
Controls built into the operation.
Nexus combines application controls, tenant-aware data access and operational monitoring to protect the work entrusted to the platform.
Access and isolation
Authentication is required for protected product routes. Workspace and organization identifiers are validated at service boundaries so users can only access data permitted by their membership and role.
Administrative accountability
Role-aware controls restrict sensitive settings and administrative actions. Audit history supports investigation of important workspace activity and configuration changes.
Application and infrastructure
Production health monitoring covers the application, database and queue infrastructure. Errors are captured through server and browser telemetry, while protected endpoints reject anonymous requests.
Encryption and credentials
Nexus Vault and stored integration credentials use AES-256-GCM authenticated encryption. Sensitive values are excluded from normal list queries, and encryption keys are supplied through protected environment configuration rather than stored with encrypted records.
Backups and recovery
Production operations require provider-managed continuous database backups, encrypted snapshots and quarterly restoration drills into an isolated environment. Recovery evidence records the snapshot, restored collection checks and accountable operator. Production restore and rollback exercises are performed during controlled maintenance windows.
Incident response
Security incidents are classified by impact. High-severity incidents receive an incident commander, timestamped record, evidence preservation, containment, recovery communications and a review within five business days.
Data retention and hosting
Immutable administrative audit records expire after two years. Public conversion events expire after approximately thirteen months. Nexus is currently delivered through Vercel and Railway with MongoDB and Redis services; specific data-location commitments are documented in the applicable organization agreement rather than inferred from a visitor's location.
Responsible disclosure
Security concerns should include the affected URL, reproducible steps and likely impact. Do not include passwords, private keys or customer data in an initial report.