Trust & Security
This page is maintained by the NexusDiligence team to answer common security, privacy, and data-handling questions about the NexusDiligence platform. It describes controls currently enabled in the app and our operating practices.
Access & authentication
Sign-in is handled by managed authentication with email/password and Google sign-in. Sessions use secure tokens with automatic refresh, and users can sign out from any device via the account menu.
Access to project data is scoped per project. Platform admins, client admins, and project members each see only the projects they have been granted access to.
Hosting & platform
NexusDiligence runs on managed cloud infrastructure with TLS for data in transit between users, the application, and our database. Database storage is encrypted at rest by our managed backend provider.
Row-level security policies are enabled on customer data tables so that the database itself enforces project- and role-based access, not just the application layer.
Data we collect
We collect the data customers enter to perform due diligence: project details, uploaded documents and notes, DDQ answers, findings, remediation tasks, scorecards, and team membership. We also collect account information (name, email, role) and audit metadata about sensitive actions.
We do not sell customer data and we do not use customer project content to train third-party models.
Subprocessors & integrations
We rely on a small set of subprocessors to operate the service, including our managed database/auth provider, our email delivery provider, and our payment processor. If you need the current list for vendor review, contact us at the address below.
Cookies & analytics
We use only the cookies required to keep you signed in and to remember your preferences. We do not run third-party advertising trackers on the application.
Retention & deletion
Project data is retained while the project is active. Customers can request export or deletion of a project's data by contacting us. Audit log entries for sensitive actions are retained for operational and security purposes.
Privacy requests
To request access to, correction of, or deletion of your personal data, email us at the security contact below. We will verify your identity before acting on the request.
Security contact & vulnerability reporting
Report suspected security issues to nandch@nexus-diligence.com. Please include reproduction steps and avoid accessing data that is not your own. We acknowledge reports promptly and will keep you updated as we investigate.
Last updated: maintained by NexusDiligence. For binding terms, see the agreement signed with your engagement.