This public Security Policy describes the security principles NEXUS PROJECT applies to its website, accounts, APIs, research systems and supporting infrastructure, together with the channel for good-faith vulnerability reporting.
NEXUS treats information security as a management and system-design responsibility. Security considerations form part of architecture, operations, vendor selection and material production changes.
Security controls are selected according to operational risk, contractual requirements, applicable legal obligations and the sensitivity of information processed by the platform.
Material security exceptions should be documented with a business justification, accountable risk owner, compensating controls and a defined review or expiry point.
NEXUS reviews security requirements when material incidents, architecture changes, provider changes or significant operational risks require reassessment.
Privileged access is intended to be limited to authorized personnel and services with a defined operational need. Administrative access should be reviewed when roles or responsibilities change.
Multi-factor authentication is expected for administrative cloud, source-control, email and other critical services where supported by the relevant provider.
Passwords, private keys, API keys and authentication secrets must not be committed to public source code or intentionally exposed in public documentation. Application secrets are intended to remain in approved server-side secret or environment-variable mechanisms.
Where NEXUS account sessions are used, the platform applies secure cookie controls and separates private publisher administration from ordinary public account access.
Material production changes should have a clear purpose, responsible owner, implementation record and an appropriate rollback or recovery path.
Changes affecting authentication, authorization, data access, security headers, APIs or administrative functions should receive additional review and testing appropriate to their risk.
NEXUS publishes transport, content, framing, referrer and browser-permission security controls at the delivery edge. Current external evidence is available through the Trust Center and Security Assessments pages.
Urgent security or availability fixes may follow an expedited path when necessary, with retrospective review and documentation after service is stabilized.
NEXUS uses security testing and external assessment evidence to identify weaknesses in public-facing systems. Findings are prioritized according to severity, exploitability and potential impact.
Critical and high-severity findings receive priority attention. Remediation should be documented and, where appropriate, independently or technically re-verified.
NEXUS does not claim an independent penetration-test attestation unless an authorized, scoped and independent assessment has actually been completed and current evidence is available.
Cloud, data, AI, software and other service dependencies are reviewed as part of platform risk because provider changes, outages or incidents can affect NEXUS security and availability.
Critical authentication, administrative, deployment, API and error events should be logged where technically feasible. Logs should not intentionally contain passwords, private keys or full authentication secrets.
Security incidents are handled according to impact and urgency. Response priorities include containment, preservation of relevant evidence, service recovery, corrective action and required communications.
Critical configuration and data should have recovery mechanisms appropriate to the architecture. Recovery procedures and key dependencies are reviewed as part of continuity planning.
Material incidents should produce a documented timeline, root-cause review where feasible, corrective actions and follow-up appropriate to the nature of the event.
NEXUS uses sensitivity and business need as the basis for handling information. Personal and confidential information should be limited to an identified purpose and protected according to risk.
Retention should reflect operational, legal, contractual, security and provider requirements. Significant data sets should have an appropriate deletion, archival or lifecycle approach.
NEXUS aims to keep user-facing privacy disclosures consistent with actual platform processing. The current Privacy & Data Protection notice is published separately.
Security and privacy considerations are reviewed before introducing material new providers where their services, data access or operational criticality can materially change NEXUS risk.
Send suspected security issues to admin@nexsusproject.ai. Include the affected URL or surface, steps to reproduce, observed impact, supporting evidence and a reliable way to contact you.
Please avoid service disruption, destructive testing, social engineering, credential attacks, privacy violations or accessing data beyond what is necessary to demonstrate the issue. Stop testing if you encounter sensitive information that is not yours.
Please do not publicly disclose an unremediated vulnerability before NEXUS has had a reasonable opportunity to investigate and respond. We aim to acknowledge and triage reports according to severity and available evidence.
This policy is not a promise of monetary reward and does not authorize testing of third-party systems, physical facilities or infrastructure that NEXUS does not control. Provider and applicable legal restrictions continue to apply.
NEXUS aims to maintain security evidence as part of ordinary operations rather than reconstructing it only for an audit. Claims about certification, attestation, penetration testing or external validation are intended to be made only when supported by current independent evidence.