Home Security, Privacy & Trust
๐Ÿ”

Security, Privacy & Trust

Data residency (EU-hosted), encryption at rest/in transit, GDPR alignment, audit trail, retention policy.
By Eliseo Thrope
โ€ข 3 articles

How NexCyber protects your data

TL;DR ๐Ÿ” EU-sovereign, EU-hosted, EU-only data plane. All your evidence and reports are encrypted at rest and in transit, isolated per tenant, and never leave the EU. ๐Ÿฐ Data residency - ๐Ÿ‡ช๐Ÿ‡บ Primary: EU hosting (Germany / France) - ๐Ÿ‡ช๐Ÿ‡บ Backups: EU-only - ๐Ÿšซ No extra-EU transfers for compliance logic or evidence storage ๐Ÿ”’ Encryption | Layer | Mechanism | |---|---| | In transit | TLS 1.3 | | At rest | AES-256 | | Database | Transparent disk encryption + per-tenant key isolation | | Backups | Encrypted with separate KMS keys | ๐Ÿ›ก๏ธ Isolation - โœ… Logical multi-tenant with row-level isolation - โœ… Per-tenant cryptographic keys - โœ… No cross-tenant data ever exposed ๐Ÿ“‹ What we never do - โŒ Train models on your data - โŒ Share data with third parties for ads or analytics - โŒ Send your evidence to external LLM providers โžก๏ธ Next - ๐Ÿ“œ Vulnerability disclosure policy - ๐ŸŒ Sub-processors list ๐Ÿ’ฌ Need help? Reach out via our live chat (bottom-right) โ€” Captain AI replies instantly, human experts within business hours. Email support@nexcyber.eu with [P1] for Command/Strategic priority issues. โ„น๏ธ Disclaimer โ€” NexCyber provides a readiness analysis, not legal advice. Final compliance may require legal review or notified body certification. Last reviewed: 2026-06-02 ยท NexCyber Help Center

Last updated on Jun 02, 2026

Responsible Vulnerability Disclosure

TL;DR ๐Ÿ›ก๏ธ We welcome good-faith security research. Report via security@nexcyber.eu (PGP key below). Safe harbor for in-scope, in-policy research. ๐Ÿ“ฅ How to report - โœ‰๏ธ Email: security@nexcyber.eu - ๐Ÿ”‘ PGP fingerprint: published at https://nexcyber.eu/.well-known/security.txt (RFC 9116) - ๐Ÿ“‹ Include: affected component, vulnerability type, reproduction steps, impact, your contact โœ… In scope - nexcyber.eu (the live app) - api.nexcyber.eu (backend API) - support.nexcyber.eu, docs.nexcyber.eu (support stack) ๐Ÿšซ Out of scope - nexcyber.eu (parking page โ€” not the live app) - DoS / volumetric attacks - Social engineering of our team - Vulnerabilities requiring physical access โš–๏ธ Safe harbor Good-faith research, within scope, without data exfiltration โ†’ no legal action. Please don't test on production without authorization. โฑ๏ธ Our commitments - ๐Ÿ“ฉ Acknowledgment: within 24 hours - ๐Ÿ” Triage: within 3 business days - ๐Ÿ” Regular updates until resolution - ๐Ÿ† Optional Hall of Fame credit โžก๏ธ Next - ๐Ÿ” How we protect your data - ๐ŸŒ Sub-processors list ๐Ÿ’ฌ Need help? Reach out via our live chat (bottom-right) โ€” Captain AI replies instantly, human experts within business hours. Email support@nexcyber.eu with [P1] for Command/Strategic priority issues. โ„น๏ธ Disclaimer โ€” NexCyber provides a readiness analysis, not legal advice. Final compliance may require legal review or notified body certification. Last reviewed: 2026-06-02 ยท NexCyber Help Center

Last updated on Jun 06, 2026