Nexus by IK Studios
Trust Center

How Nexus keeps your company safe

A single place for how we handle security, access, and data. We are transparent about what is in place today and what we are still building.

Security overview

The controls in place today

Multi-factor authentication

TOTP, WebAuthn / Touch ID, and trusted-device QR approval.

Row-level security

Data is isolated at the database row, not just the application layer.

Trusted devices

Link and verify the devices allowed to approve sensitive actions.

Least-privilege RBAC

People see only what their role allows, edited from a live matrix.

Reason-required admin actions

Sensitive changes demand a written, logged reason.

Audit logging

A company-wide, queryable record of who did what, and why.

Access & governance

Access is granted narrowly and recorded fully

RBAC is live today. Attribute-based access control (ABAC) and enterprise single sign-on are planned.

Least-privilege by default

Role-based access control, edited from a live permission matrix.

Reason-required actions

Sensitive admin changes capture a written reason for the audit log.

Full audit trail

A company-wide, queryable record of who did what, and why.

Data protection & compliance

An honest posture

Built in the EU

Available

Nexus is developed and operated in the European Union.

GDPR tooling

Available

Data-subject exports and recorded consent in the Super Admin Hub.

Formal certifications

Working toward

We describe our posture honestly and do not claim credentials we do not hold.

Data-residency options

Planned

Regional residency for Enterprise editions.

Subprocessors

Nexus relies on a small set of infrastructure providers for hosting, identity, and monitoring. A current subprocessor list is available to customers and prospects under review.

Request the list

Responsible disclosure

If you believe you have found a security issue, we want to hear from you. Report it privately and we will respond promptly.

security@ikstudios.nl

Pre-general-availability

Nexus is offered through a design-partner and early-access programme. Multi-tenant isolation is planned; today, environments are configured and reviewed with each organisation.

Get started

Run a security review with us

Bring your questionnaire. We will answer against what is live today and what is on the roadmap.