Bank-grade security.
Without the enterprise ceremony.
Strong encryption at rest and in transit. Single Sign-On and two-factor authentication. Per-tenant data isolation. Self-service data deletion. Full audit trail retained for years, not months.
Encryption
All data is encrypted in transit and at rest using current industry-standard algorithms. Session cookies are HttpOnly + Secure + SameSite=lax to prevent interception. Database-level encryption uses managed keys; document storage uses server-side encryption with per-tenant key separation.
Authentication
Email + password (modern memory-hard hashing with per-user salt) or Single Sign-On against any standards-compliant enterprise identity provider. Password policy enforces minimum length and common-pattern rejection. Account lockout after repeated failed attempts.
Multi-Factor Authentication (MFA)
Two-factor authentication available on all tiers, compatible with any standard authenticator app. Enterprise tenants can force MFA org-wide via policy. MFA secrets are encrypted server-side. Recovery codes are stored under one-way hashing.
SSO / JIT Provisioning (Enterprise tier)
Single Sign-On against any standards-compliant enterprise identity provider, with just-in-time user provisioning — new users at your identity provider automatically get an account on first sign-in with role mapped from your directory attributes. Force-SSO policies block password sign-in for corporations that require it. Full configuration from Settings → SSO. Available on Enterprise plans; see the pricing page for details.
Audit Logs
Every authentication event, permission change, invoice approval, data export, and platform admin action is written to an immutable audit log. Logs are backed up daily and append-only. Account Owners and platform admins can review the full activity trail in-app. Retained for 7 years.
Data Isolation
Per-tenant database isolation. Each corporation's data lives in its own database namespace — no shared tables, no cross-tenant queries. Every tenant has its own NexosIQ Learn vector store. Access is enforced at the connection layer, not application-level filtering.
Infrastructure
Hosted on a tier-1 cloud provider with auto-scaling compute in private network subnets, managed database with point-in-time recovery, encrypted object storage with lifecycle policies, and edge CDN with strict transport security. Detailed infrastructure architecture is available under NDA.
Compliance Posture
Audit-track controls implemented; independent Type II attestation in progress. GDPR-compliant (EU data subject rights: erasure, portability, access — all self-service). CCPA-compliant. Ongoing independent penetration testing. Current attestation status and completed security questionnaires (SIG Lite, CAIQ) available under NDA.
Data Retention & Right to Erasure
Default 3-year retention per tenant (configurable via Unlimited Retention add-on). Weekly cleanup with 30-day advance warning emails. Soft-deleted items hard-purge after 90 days. User-initiated account deletion — 30-day grace period, then PII anonymization while preserving audit trail user IDs for compliance.
Incident Response
24/7 server-side monitoring with structured error logs and audit trail; native mobile crash reporting. Security-sensitive events (failed MFA attempts, mass downloads, unusual admin actions) are written to the audit log and trigger alerts. Breach notification policy follows regulatory 72-hour notification windows. Dedicated security contact: security@nexosscan.com.
Full Security & Compliance Posture
Detailed posture document covering data isolation, authentication, encryption, network controls, audit retention, intelligent automation guardrails, infrastructure, business continuity, sub-processors, and data subject rights. Designed for enterprise InfoSec teams and vendor security questionnaires.
Responsible Disclosure
Found a security issue? Please email security@nexosscan.com with reproducible details. We acknowledge receipt within two business days and treat every report seriously. No automated scanners against production, please.
The full posture, under NDA
For IT, security, and compliance teams running their evaluation: current attestation status, completed questionnaires (SIG Lite, CAIQ), infrastructure architecture, and pen-test summary are available under NDA. Contact us and we'll send it over.
See pricing