Security at Nexus Compliance

Nexus Compliance is a governance product. We hold ourselves to the same standard we hold the agents we certify.

USPTO 19/571,156 Governedware Encryption in transit Encryption at rest No training on customer data

Data handling

When you call the Nexus Compliance API, your agent output is transmitted over HTTPS (TLS 1.2+), evaluated against the selected regulatory framework, and a certification receipt is generated. The evaluation happens in real time.

Authentication and access

Every authenticated API call requires a bearer token issued by Nexus Compliance. Keys are SHA-256 hashed before storage — we never store raw API keys.

Infrastructure

Certification integrity

The compliance gate itself is the product. Its integrity is non-negotiable.

Compliance frameworks

Nexus Compliance currently certifies agent output against three regulatory frameworks:

Enterprise customers can define custom compliance frameworks via the dashboard.

Data processing agreement

Enterprise customers requiring a formal Data Processing Agreement can contact us at info@debacconexus.com. Our standard DPA covers data handling, retention, sub-processors, breach notification, and GDPR compliance.

Responsible disclosure

If you discover a security vulnerability in Nexus Compliance, please report it to info@debacconexus.com with the subject line "Security Disclosure." We will acknowledge receipt within 24 hours and provide an initial assessment within 72 hours.