In one paragraph
We treat customer data as the most sensitive asset we hold. NexCyber runs on EU infrastructure, encrypts data in transit and at rest, isolates tenants logically, audits sensitive actions, and minimises the personal data we process. This article walks the controls, the sub-processor model, the operational hygiene, and what we never do.
Hosting and residency
- NexCyber platform components run on EU infrastructure.
- Customer data — assessments, evidence, contracts, MRCCs, advisories — is stored in the EU.
- Backups remain in the EU and are encrypted at rest.
- Operational telemetry processed by our engineering team also lives in the EU.
For customers with stricter residency expectations (regulated entities, public sector, defence-adjacent), we offer region-pinning attestation per release and customer-managed encryption keys on Command / Strategic plans. See Data residency and sub-processors.
Encryption
- In transit : TLS for all client and inter-service connections.
- At rest : AES-256 encryption for primary datastores and object storage that holds evidence.
- Key management : keys live in a managed KMS with rotation policy; access to KMS is logged separately from the application.
- MRCC and Trust Passport signing : Ed25519 chain (
nexcyber_signer); the public key is published on the Trust Center.
Tenant isolation
- Each customer's data lives in an isolated logical tenant.
- Cross-tenant access is not possible from the application layer.
- Workspace identifiers are propagated in every internal request; verification happens at the boundary of every service.
- Test data and production data do not share infrastructure beyond the tenant boundary.
Access controls
Inside NexCyber :
- Strict role separation. Access to customer data requires a business reason and is audited.
- Multi-factor authentication is required for staff with platform access.
- Just-in-time elevation is used for sensitive operations (no standing privileges).
- Joiner / mover / leaver discipline is documented and exercised.
Customer-side :
- You control your team's roles via the workspace UI.
- Built-in roles : Owner / Admin / Member / Viewer.
- Custom roles are available on Strategic.
- SSO / SAML / OIDC is offered on Command and above.
Audit logging
Sensitive actions are logged with actor, timestamp, and target. The audit trail will move to a hash-chained, append-only format (Merkle-like, signed with nexcyber_signer) on the next platform release per the security amendments to the support plan.
You can request your tenant audit log for review at any time via a support conversation.
Sub-processors
A current list of sub-processors is available on request and is reviewed annually. Categories typically present :
- Infrastructure provider — compute, storage, network in EU regions.
- Email delivery — transactional email for account notifications + digests.
- Observability — logs, metrics, traces of our own services (no customer evidence content).
- Customer-support tooling — the chat widget and Help Center backend.
Each sub-processor is bound by a Data Processing Addendum. Material changes are notified in advance per the SLA in your DPA.
Personal data
The personal data we process is operational : account users, contact details for support, audit log identities. We minimise it by design.
- We do not use customer evidence content to train external models.
- We do not share customer data across tenants.
- We do not sell or rent customer data to third parties.
- We do not require unnecessary personal data at onboarding.
Data export and deletion
- Export : you can export your data at any time.
- Deletion : you can request deletion in line with our terms. We honour applicable retention requirements.
- DSR (Data Subject Requests) : structured workflow for export / delete / rectify, with a 30-day max ceiling per security amendment D4 of the support plan.
Operational hygiene we follow
- Patching cadence : security updates within defined SLAs based on severity.
- Penetration testing : annual third-party assessment + continuous internal testing.
- Incident response : documented playbook, on-call rota, exercised quarterly.
- Backup discipline : 3-2-1 strategy; restores tested.
- Disaster recovery : RTO / RPO targets documented per service tier.
- Bug bounty / vulnerability disclosure : public RFC 9116 policy at
support.nexcyber.eu/.well-known/security.txtanddocs.nexcyber.eu/.well-known/security.txt.
Compliance posture
- GDPR Article 28-compliant DPA available on request.
- SOC 2 Type II — alignment in progress, attestation expected in coming quarters.
- ISO 27001 — alignment in progress with documented control mapping.
- DORA — internal alignment + readiness for in-scope customers.
- NIS2 — Article 21 measures implemented at our operating level.
We do not over-state certifications. When a third-party attestation is in progress, we say "in progress"; when it's certified, we publish the certificate.
What you can ask us anytime
- The current sub-processors list.
- The current DPA version.
- The infrastructure region for your tenant.
- A summary of recent security events (per your contract).
- A redacted audit log extract.
- The current incident response runbook outline.
Reporting a concern
If you suspect a security issue affecting your data :
- For confirmed vulnerabilities → email
security@nexcyber.eu(RFC 9116 policy applies). - For data-handling concerns → contact
trust@nexcyber.euor open a support conversation. - For incident response → use your dedicated channel if Command / Strategic; otherwise the support widget.
We acknowledge security reports within 2 business days and triage within 5 business days. See Responsible vulnerability disclosure.
What we never do
- Use customer evidence to train external models.
- Share customer data across tenants.
- Sell or rent customer data.
- Silently change residency without notice.
- Process more personal data than necessary.
Related articles
- Data residency and sub-processors.
- Responsible vulnerability disclosure.
- What NexCyber does NOT replace.
Next step
For most customers, no action is required — this article documents the baseline. For customers with stricter residency or compliance expectations, request a residency-aware configuration via the widget.