1. Program Overview
NexusSeal maintains an information security program aligned with industry best practices, including controls mapped to SOC 2 trust services criteria. Formal SOC 2 attestation is a roadmap item.
2. Encryption
Data in transit is protected by TLS 1.2+; data at rest is encrypted using AES-256 or stronger. Recordings of notarial sessions are stored encrypted with key management controls.
3. Access Control
Role-based access control, least-privilege provisioning, multi-factor authentication for administrative access, and continuous logging of privileged operations.
4. Network Security
Segmented production environments, hardened images, infrastructure-as-code, and continuous vulnerability scanning.
5. Application Security
Secure software development lifecycle including code review, static analysis, dependency scanning, and Row-Level Security on database tables containing customer or signer data.
6. Monitoring & Incident Response
Continuous monitoring, alerting, and a documented incident response plan. We will notify affected customers without undue delay when notice is legally required or contractually agreed.
7. Business Continuity
Daily backups, redundant infrastructure, and tested recovery procedures.
8. Vendor Risk
Sub-processors are reviewed before onboarding and re-assessed periodically.
9. Responsible Disclosure
Report suspected vulnerabilities via our contact page. We do not pursue legal action against good-faith security research conducted in accordance with this policy.
This document is Version 1.0 and is subject to future updates as regulations, product capabilities, and industry standards evolve. For questions, contact ROSSNEXUS Technologies LLC.