How we protect your data and secure the platform.
All data encrypted at rest and in transit. TLS 1.3 for all connections. Passwords hashed with bcrypt. API keys stored with AES-256 encryption.
Secure session management with CSRF protection. Credential-based authentication with rate limiting on login attempts.
Hosted on secured cloud infrastructure with automated backups. Database connections encrypted. Network-level isolation between services.
Principle of least privilege across all systems. No employee access to user credentials or API keys. Audit logging on sensitive operations.
If you discover a security vulnerability, please report it responsibly. Do not publicly disclose the issue until we have had an opportunity to address it.
Report vulnerabilities to hello@nexushq.xyz. Include a detailed description of the vulnerability and steps to reproduce. We aim to acknowledge reports within 24 hours and provide resolution timelines within 72 hours.