Trust Center — Compliance & Security
The evidence your security and procurement teams need. Compliance posture, sub-processors, pen-test summary, encryption and vulnerability disclosure. One page, no chasing.
Compliance & certifications — aligned with the regulators your auditors report to: SOC 2 Type II (in progress, annual audit programme starting 2026), ISO/IEC 27001 (in progress, initial certification target 2026), GDPR (aligned, EU data subject rights, DPA on request), Swiss nFADP (aligned, by design), MAS TRM (aligned, Monetary Authority of Singapore), BNM RMiT (aligned, Bank Negara Malaysia), PDPA — SG, MY, TH (aligned, per-country data protection regimes), OJK (aligned, Indonesian financial services authority).
Security posture — how we keep your data, in your jurisdiction:
Encryption — AES-256 at rest, TLS 1.3 in transit, per-tenant key isolation, customer-managed keys on request.
Residency — data processed and stored in the region you choose (SG, MY, ID, CH), no cross-region replication without explicit consent.
Audit logs — every action, analyst, agent and admin, is logged with tamper-evident hashes, exportable to your SIEM.
Pen testing — annual third-party penetration tests, summary report available under NDA via the request form.
Background checks — all personnel with production access undergo background checks, access is least-privilege and time-bound.
Incident response — 24/7 on-call, customer notification within 4 hours of confirmed incident, post-incident report within 5 business days.
Sub-processors, reviewed annually, customers notified 30 days before any addition: ITNB AG (Switzerland — engineering partner, model and platform development), cloud providers (selected per region — tenant-isolated infrastructure), identity/Auth0/WorkOS (per region — SSO/SAML/OIDC brokering only), observability (internal — self-hosted telemetry, no customer data sent to third parties).
Vulnerability disclosure: we operate a coordinated disclosure programme, security researchers acting in good faith will not face legal action. Report to security@nexulis.com (PGP key on request), acknowledged within 2 business days, triaged within 5, coordinated disclosure timeline up to 90 days.
Get a demo · Visit NEXULIS