Skip to content
Nexus365

Security

Security is part of the design, not an add-on

Commerce data — sales, stock, credit and customer details — needs careful handling. These are the controls Nexus365 is built around.

Draft — to be reviewed before launch. This page describes design principles and planned controls for the platform, which is in development. Nexus365 does not currently hold any security certification, and we won't display badges until one is independently awarded.
  • Tenant isolation

    Every record belongs to an organisation, and access is enforced in trusted server code and the database — never only by filtering in the browser.

  • Role-based access

    Roles and branch permissions decide who can sell, discount, refund, approve purchases, see margins or export data.

  • Audit logs

    Sensitive actions — price changes, refunds, approvals, permission changes — are recorded with who, what and when.

  • Encryption in transit

    All traffic to the website and platform is served over HTTPS with modern TLS and HSTS.

  • Secure authentication

    Established authentication, secure password reset, session management and optional multi-factor authentication are planned for platform sign-in.

  • Backups and recovery

    Backup and restore procedures for customer data will be defined and tested before the platform hosts live businesses.

Transactional integrity

Inventory, sales and financial postings are designed to succeed or fail together, with balanced journal entries and idempotent processing so that a retried request — for example from an offline POS — never posts twice.

Secrets and integrations

API keys and integration credentials are kept in server-side secret storage and are never exposed in browser code.

AI and privacy

AI features work on an organisation's own data inside its workspace, and consequential actions require human approval. See Data Processing.

Reporting a vulnerability

If you believe you've found a security issue, please tell us through the contact page and include the word “Security” in your message. Please don't access data that isn't yours or disrupt the service while testing. A dedicated disclosure channel will be published before launch.