SECURITY POLICY

Protect the system.
Preserve the evidence.

This public Security Policy describes the security principles NEXUS PROJECT applies to its website, accounts, APIs, research systems and supporting infrastructure, together with the channel for good-faith vulnerability reporting.

Effective 23 September 2026 · Version 1.0 · Public Policy
Security Governance

Risk-based controls and accountable operation.

GovernanceSecurity is an operating responsibility

NEXUS treats information security as a management and system-design responsibility. Security considerations form part of architecture, operations, vendor selection and material production changes.

RiskControls follow risk and data sensitivity

Security controls are selected according to operational risk, contractual requirements, applicable legal obligations and the sensitivity of information processed by the platform.

ExceptionsMaterial exceptions require ownership

Material security exceptions should be documented with a business justification, accountable risk owner, compensating controls and a defined review or expiry point.

ReviewPolicy and controls evolve

NEXUS reviews security requirements when material incidents, architecture changes, provider changes or significant operational risks require reassessment.

Identity & Access

Restrict privileged access and protect credentials.

Least PrivilegeAccess follows operational need

Privileged access is intended to be limited to authorized personnel and services with a defined operational need. Administrative access should be reviewed when roles or responsibilities change.

AuthenticationUse stronger controls for critical systems

Multi-factor authentication is expected for administrative cloud, source-control, email and other critical services where supported by the relevant provider.

SecretsKeep keys out of public code

Passwords, private keys, API keys and authentication secrets must not be committed to public source code or intentionally exposed in public documentation. Application secrets are intended to remain in approved server-side secret or environment-variable mechanisms.

SessionsProtect browser sessions

Where NEXUS account sessions are used, the platform applies secure cookie controls and separates private publisher administration from ordinary public account access.

Secure Engineering

Make production changes reviewable and reversible.

Change ManagementIdentify purpose, owner and rollback path

Material production changes should have a clear purpose, responsible owner, implementation record and an appropriate rollback or recovery path.

Security-sensitive ChangesTest before and verify after deployment

Changes affecting authentication, authorization, data access, security headers, APIs or administrative functions should receive additional review and testing appropriate to their risk.

Platform HardeningBrowser and edge protections

NEXUS publishes transport, content, framing, referrer and browser-permission security controls at the delivery edge. Current external evidence is available through the Trust Center and Security Assessments pages.

Emergency ChangesRestore first, document afterwards

Urgent security or availability fixes may follow an expedited path when necessary, with retrospective review and documentation after service is stabilized.

Vulnerability Management

Find, prioritize, remediate and verify.

DetectionAssess internet-facing surfaces

NEXUS uses security testing and external assessment evidence to identify weaknesses in public-facing systems. Findings are prioritized according to severity, exploitability and potential impact.

RemediationTrack material findings to closure

Critical and high-severity findings receive priority attention. Remediation should be documented and, where appropriate, independently or technically re-verified.

Penetration TestingNo unsupported assurance claims

NEXUS does not claim an independent penetration-test attestation unless an authorized, scoped and independent assessment has actually been completed and current evidence is available.

DependenciesThird-party changes can change risk

Cloud, data, AI, software and other service dependencies are reviewed as part of platform risk because provider changes, outages or incidents can affect NEXUS security and availability.

Monitoring, Incidents & Recovery

Preserve useful records and recover deliberately.

LoggingRecord security-relevant events where practical

Critical authentication, administrative, deployment, API and error events should be logged where technically feasible. Logs should not intentionally contain passwords, private keys or full authentication secrets.

Incident ResponseContain, preserve evidence, recover

Security incidents are handled according to impact and urgency. Response priorities include containment, preservation of relevant evidence, service recovery, corrective action and required communications.

RecoveryIdentify recovery mechanisms for critical systems

Critical configuration and data should have recovery mechanisms appropriate to the architecture. Recovery procedures and key dependencies are reviewed as part of continuity planning.

LearningMaterial incidents drive corrective action

Material incidents should produce a documented timeline, root-cause review where feasible, corrective actions and follow-up appropriate to the nature of the event.

Data & Third Parties

Protect information according to sensitivity.

ClassificationPublic, Internal, Confidential, Restricted

NEXUS uses sensitivity and business need as the basis for handling information. Personal and confidential information should be limited to an identified purpose and protected according to risk.

RetentionKeep data only for a defined need

Retention should reflect operational, legal, contractual, security and provider requirements. Significant data sets should have an appropriate deletion, archival or lifecycle approach.

PrivacyPublic notices should match actual processing

NEXUS aims to keep user-facing privacy disclosures consistent with actual platform processing. The current Privacy & Data Protection notice is published separately.

VendorsReview material dependencies

Security and privacy considerations are reviewed before introducing material new providers where their services, data access or operational criticality can materially change NEXUS risk.

Responsible Disclosure

Report suspected vulnerabilities privately.

ContactSecurity reports

Send suspected security issues to admin@nexsusproject.ai. Include the affected URL or surface, steps to reproduce, observed impact, supporting evidence and a reliable way to contact you.

Good-faith ResearchMinimize impact

Please avoid service disruption, destructive testing, social engineering, credential attacks, privacy violations or accessing data beyond what is necessary to demonstrate the issue. Stop testing if you encounter sensitive information that is not yours.

DisclosureGive NEXUS time to investigate

Please do not publicly disclose an unremediated vulnerability before NEXUS has had a reasonable opportunity to investigate and respond. We aim to acknowledge and triage reports according to severity and available evidence.

BoundariesNot a public bug-bounty authorization

This policy is not a promise of monetary reward and does not authorize testing of third-party systems, physical facilities or infrastructure that NEXUS does not control. Provider and applicable legal restrictions continue to apply.

The machine-readable security contact is published at /.well-known/security.txt.
Assurance & Claims

Publish evidence without overstating maturity.

Current Public EvidenceExternally visible security posture
Security headers and transport controlsPublished
Responsible disclosure / security.txtPublished
Independent security-assessment evidencePublished
Current Assurance BoundaryClaims we do not make without evidence
Independent penetration-test attestationNot claimed
ISO/IEC 27001 certificationNot certified
SOC 2 attestationNot attested
Continuous ImprovementEvidence should be maintained over time

NEXUS aims to maintain security evidence as part of ordinary operations rather than reconstructing it only for an audit. Claims about certification, attestation, penetration testing or external validation are intended to be made only when supported by current independent evidence.

Policy Scope

Public baseline, not a certification statement.

This page is a public summary of NEXUS PROJECT security principles and disclosure expectations. Detailed internal procedures, control ownership and operating evidence are maintained separately and may evolve as the platform changes. Publication of this page does not by itself constitute ISO certification, SOC attestation, regulatory approval, or an independent penetration-test opinion.