Security

Controls built into the operation.

Nexus combines application controls, tenant-aware data access and operational monitoring to protect the work entrusted to the platform.

Access and isolation

Authentication is required for protected product routes. Workspace and organization identifiers are validated at service boundaries so users can only access data permitted by their membership and role.

Administrative accountability

Role-aware controls restrict sensitive settings and administrative actions. Audit history supports investigation of important workspace activity and configuration changes.

Application and infrastructure

Production health monitoring covers the application, database and queue infrastructure. Errors are captured through server and browser telemetry, while protected endpoints reject anonymous requests.

Encryption and credentials

Nexus Vault and stored integration credentials use AES-256-GCM authenticated encryption. Sensitive values are excluded from normal list queries, and encryption keys are supplied through protected environment configuration rather than stored with encrypted records.

Backups and recovery

Production operations require provider-managed continuous database backups, encrypted snapshots and quarterly restoration drills into an isolated environment. Recovery evidence records the snapshot, restored collection checks and accountable operator. Production restore and rollback exercises are performed during controlled maintenance windows.

Incident response

Security incidents are classified by impact. High-severity incidents receive an incident commander, timestamped record, evidence preservation, containment, recovery communications and a review within five business days.

Data retention and hosting

Immutable administrative audit records expire after two years. Public conversion events expire after approximately thirteen months. Nexus is currently delivered through Vercel and Railway with MongoDB and Redis services; specific data-location commitments are documented in the applicable organization agreement rather than inferred from a visitor's location.

Responsible disclosure

Security concerns should include the affected URL, reproducible steps and likely impact. Do not include passwords, private keys or customer data in an initial report.

Report a security concern

Security | Nexus