Security is the foundation, not an add-on
Access is least-privilege by default, data is isolated at the row, and sensitive actions leave a reason and a trail. The controls a security team expects are built into the platform, not bolted on.
What protects your company today
Multi-factor authentication
TOTP, WebAuthn / Touch ID, and trusted-device QR approval.
Row-level security
Data is isolated at the database row, not just the application layer.
Trusted devices
Link and verify the devices allowed to approve sensitive actions.
Least-privilege RBAC
People see only what their role allows, edited from a live matrix.
Reason-required admin actions
Sensitive changes demand a written, logged reason.
Audit logging
A company-wide, queryable record of who did what, and why.
Data residency
Built in the EU. Data-residency options are planned for the Enterprise editions.
GDPR tooling
Data-subject exports and recorded consent are available in the Super Admin Hub today.
Encryption
Data is encrypted in transit. Managed Postgres provides encryption at rest.
Where our security model is heading
We label planned work honestly. These are designed and roadmapped, not yet shipped.
Attribute-based access (ABAC)
Fine-grained rules layered on top of roles.
SSO / SAML
Enterprise single sign-on and directory federation.
Break-glass access
Audited emergency elevation during incidents.
Tenant isolation
Per-organisation isolation for commercial SaaS.
A note on compliance
Nexus is built in the EU with GDPR tooling available today. We describe our posture as working toward formal certifications rather than claiming credentials we do not yet hold.
Bring your security team to the demo
We will walk through the access model, audit trail, and data protection in detail.