Nexus Trust Center

Enterprise security, privacy and compliance documented,independently audited and third-party verified.

Every control below governs the platform your operations, finance and customer data run on. Assurance reports are available to prospects, customers and auditors under a confidentiality agreement.

All Systems OperationalSecurity OverviewSystem Status

Certifications & Attestations

Independently examined and third-party verified

Hover any badge for the issuing body, the scope of the assessment and its current status.

ISAE 3402 Type II

ISAE 3402 Type II

Audit Completed

ISAE 3402 Type II

International Auditing and Assurance Standards Board

Third-party assurance report for service organizations, covering the design and operating effectiveness of controls over the reporting period.

Audit Completed
PCI Security Standards Council

PCI Security Standards Council

Participating Organization

PCI Security Standards Council

PCI Security Standards Council

Participating Organization. Cardholder data for POS and subscription payments is processed by our PCI DSS Level 1 payment processors; card numbers never transit or rest in platform storage.

Participating Organization
GDPR

GDPR

Compliant

GDPR

European Union — Regulation 2016/679

Data protection and sovereignty commitments covering lawful basis, data subject rights, breach notification and processor obligations.

Compliant
BSI ISO/IEC 27001

BSI ISO/IEC 27001

Certified

BSI ISO/IEC 27001

BSI (British Standards Institution)

Information Security Management System certified against ISO/IEC 27001, covering risk treatment, access control, cryptography and supplier security.

Certified
ANAB Accredited

ANAB Accredited

Accredited

ANAB Accredited

ANSI National Accreditation Board

Certification issued by a management systems certification body accredited to ISO/IEC 17021-1, establishing the competence of the certifying auditor.

Accredited
IAF MLA

IAF MLA

Recognized

IAF MLA

International Accreditation Forum

Member of the IAF Multilateral Recognition Arrangement, under which the certification is recognized across participating accreditation bodies worldwide.

Recognized

Security Controls

How the platform is protected

Control families mapped to their Trust Services Criteria references.

Logical Access

CC6.1

Identity, authorization and tenant isolation.

  • Single sign-on with OIDC identity federation
  • Role-based access control with per-action grant matrices
  • Row-Level Security enforced at the database layer, per tenant
  • Least-privilege service roles for server-side operations

Threat Prevention

CC6.8

Preventing unauthorized or malicious software and access.

  • Encryption in transit (TLS) and at rest
  • Secrets held in a managed secret store, never in source control
  • Signed and secret-verified inbound webhooks
  • Managed endpoint detection and patch compliance monitoring

System Monitoring

CC7.2

Detecting and acting on anomalies.

  • Immutable audit ledger for privileged and financial operations
  • Fail-closed audit records written before any mutation
  • Authentication event logging
  • Alert triage with severity-based escalation and SLA tracking

Change Management

CC8.1

Authorizing, testing and recording changes.

  • Versioned release manifest with a published change log
  • Reviewed changes with documented rollback paths
  • Segregated configuration per environment
  • Two-person approval for destructive remote actions

Document Vault

Assurance documentation on request

These documents are released under a confidentiality agreement and delivered by our security team.

SOC 2 Type II Report

Full attestation report covering the Trust Services Criteria over the examination period.

NDA required

Penetration Test Summary

Executive summary of the most recent third-party penetration test, including remediation status.

NDA required

Disaster Recovery Plan

Business continuity and disaster recovery procedures, including recovery objectives.

NDA required

ISO/IEC 27001 Certificate

Current certificate of registration and its statement of applicability scope.

NDA required

Privacy

Subprocessors and data residency

Subprocessors

Third parties that process data on our behalf, and the primary region each operates in.

VendorServicePrimary Region
AWSApplication hosting, managed database and file storageUnited States
CloudflareEdge delivery, object storage (R2) and transactional email transportGlobal edge network
Google Cloud / Google Workspace APIsCalendar, Drive and Gmail integrations, Maps geocodingGlobal
StripeCard and ACH payment processing, subscription billing, payoutsUnited States
PlaidBank account linking and transaction synchronizationUnited States
ResendSending-domain DKIM and SPF verificationUnited States
ApolloSales prospect enrichment for the outbound moduleUnited States
OpenRouteServiceCommercial vehicle routing and distance calculationEuropean Union
MeshCentralRemote monitoring and management sessions for managed endpointsSelf-hosted by operator