Security at Nexus Compliance
Nexus Compliance is a governance product. We hold ourselves to the same standard we hold the agents we certify.
USPTO 19/571,156
Governedware
Encryption in transit
Encryption at rest
No training on customer data
Data handling
When you call the Nexus Compliance API, your agent output is transmitted over HTTPS (TLS 1.2+), evaluated against the selected regulatory framework, and a certification receipt is generated. The evaluation happens in real time.
- Agent output is not stored. The content submitted for certification is processed in memory and discarded after the response is returned. We do not persist, log, or cache the text of your agent output.
- Receipt metadata is stored. The receipt ID, verdict, framework, check results, timestamp, and cryptographic signature are stored in our database for verification purposes. This allows any party to independently verify a receipt via our public verification endpoint.
- We do not train on your data. Agent output submitted to the API is never used to train, fine-tune, or improve any model. It is evaluated and discarded.
Authentication and access
Every authenticated API call requires a bearer token issued by Nexus Compliance. Keys are SHA-256 hashed before storage — we never store raw API keys.
- API keys are hashed at rest. Only the SHA-256 hash is stored. The raw key is shown once at generation and cannot be retrieved.
- Rate limiting is enforced per key. Each plan tier has a defined requests-per-minute ceiling. Exceeding it returns a 429 response with retry guidance.
- Key revocation is immediate. Revoking a key takes effect on the next request. There is no propagation delay.
- Admin endpoints are gated. Key management, usage data, and billing operations require a separate admin credential.
Infrastructure
- Hosted on Railway. Our application runs on Railway's managed infrastructure with automatic TLS termination, isolated containers, and continuous deployment from a private GitHub repository.
- PostgreSQL with encryption at rest. All structured data (receipts, usage logs, API key hashes) is stored in Railway-managed PostgreSQL with encryption at rest enabled by default.
- No shared tenancy on the database. Each Nexus Compliance deployment runs its own isolated database instance.
- Continuous deployment. Code is deployed from a private GitHub repository via Railway. No manual server access. No SSH.
Certification integrity
The compliance gate itself is the product. Its integrity is non-negotiable.
- Cryptographic receipts. Every certification produces a receipt with a SHA-256 content hash and a signature derived from the input, framework, and a server-side secret. The signature cannot be forged or reproduced without the signing key.
- TriStack certification. Each request passes through three independent layers: hardware production authentication, pre-inference compliance certification, and multi-media forensic analysis. One receipt covers all three.
- Public receipt verification. Any party can verify a receipt at
GET /v1/receipts/:receiptId without authentication. The verification response includes the original verdict, checks, and timestamp.
- Red team tested. Our public red team suite at /redteam.html runs 27 adversarial tests against the compliance gate — prompt injection, transparency evasion, oversight bypass, accuracy attacks, data governance violations, risk management gaps, and boundary conditions. Current score: 27/27 gate held.
Compliance frameworks
Nexus Compliance currently certifies agent output against three regulatory frameworks:
- EU AI Act — European Union Artificial Intelligence Act (Articles 9, 10, 13, 14, 15)
- NIST AI RMF — NIST AI Risk Management Framework (Govern, Map, Measure, Manage functions)
- ISO 42001 — ISO/IEC 42001 AI Management System standard
Enterprise customers can define custom compliance frameworks via the dashboard.
Data processing agreement
Enterprise customers requiring a formal Data Processing Agreement can contact us at info@debacconexus.com. Our standard DPA covers data handling, retention, sub-processors, breach notification, and GDPR compliance.
Responsible disclosure
If you discover a security vulnerability in Nexus Compliance, please report it to info@debacconexus.com with the subject line "Security Disclosure." We will acknowledge receipt within 24 hours and provide an initial assessment within 72 hours.