Trust Center
A public overview of NexaFile security, access, providers and availability. This page is not a contractual SLA.
Access controls
- Workspaces are separated by organization; Owner, Admin and Member roles limit functions by role.
- Documents remain private to their creator unless explicitly assigned or shared in the workspace.
- MFA and recovery codes are supported; recovery codes are hashed and MFA secrets are encrypted in the database.
Encryption and data transfer
Production browser connections use HTTPS. Passwords are hashed with scrypt. OAuth credentials and MFA secrets stored in the database are encrypted with the application key. Documents stored in object storage are application-encrypted before upload under the current production configuration.
AI result verification
NexaFile traces material findings to source-page content when possible, shows source coverage/confidence, and marks findings without sufficient evidence for human review. This is not a guarantee that AI is always correct.
Service providers
NexaFile uses trusted service providers to operate the platform, process payments, provide AI capabilities and connect cloud services. The providers involved depend on the features a customer chooses to use.
- DigitalOcean: application infrastructure and data storage.
- OpenAI API: AI processing for content users explicitly submit for analysis.
- Polar: hosted checkout for payment, tax and receipt processing for applicable transactions; Polar acts as Merchant of Record.
- Resend: account verification, security and service notification emails.
- Google: sign-in, Google Drive and Google services explicitly connected by the user.
- Microsoft: sign-in and OneDrive/SharePoint connections according to permissions granted by the user or organization.
- Cloudflare: DNS, edge protection and automated/bot traffic protection.
NexaFile also provides APIs and developer tools for system integrations. Client tools such as Postman may be used by customers to call the API, but they are not default NexaFile data-processing providers.
View details about data processing, security and privacy →
Review data-processing details.
Operations and incidents
Health and readiness are monitored regularly; public incidents are recorded on the Status page. NexaFile uses logging, rate limiting, audit records and incident-handling procedures. No system can promise absolute security.
Availability and SLA
NexaFile does not publish a general uptime SLA or service-credit commitment for every plan. Infrastructure-provider SLAs are not NexaFile SLAs. If an enterprise order form includes a separate SLA, only that signed SLA applies.
Public control scope
| Area | Published control | Claim boundary |
|---|---|---|
| Identity & access | MFA · Passkeys · RBAC · audit records | Does not imply third-party certification. |
| Data | HTTPS · encrypted application secrets · workspace isolation | Specific location and retention depend on configuration, providers and contract. |
| Operations | health/readiness monitoring · rate limiting · incident records | Observed measurements are not a contractual SLA. |
Subprocessors and data flow
The list above names currently published providers and their primary purposes. Actual data scope depends on the features a customer uses; not every document is sent to every provider.
NexaFile does not claim SOC 2, ISO 27001 or similar certification unless a current independent report or certificate is available.
Governance, evidence and updates
- Public statements describe controls in operation and must not be elevated into an unsigned certification, SLA or warranty.
- Material changes to providers, OAuth scope, retention or data handling must be reflected in the Trust Center or the applicable legal notice.
- Business customers may request a DPA, security questionnaire or available control evidence; disclosure remains subject to confidentiality and the applicable agreement.
Shared-responsibility model
NexaFile protects the platform and controls it operates. Customers remain responsible for user lifecycle, workspace permissions, endpoint and cloud-account security, lawful data selection, review of AI output and revoking access when no longer needed.
Report a security concern
Send a description, timestamp, affected URL and reproduction steps; do not email passwords, API keys or sensitive documents. [email protected]