Trust Center
A public overview of NexaFile security, access, providers and availability. This page is not a contractual SLA.
Access controls
- Workspaces are separated by organization; Owner, Admin and Member roles limit functions by role.
- Documents remain private to their creator unless explicitly assigned or shared in the workspace.
- MFA and recovery codes are supported; recovery codes are hashed and MFA secrets are encrypted in the database.
Encryption and data transfer
Production browser connections use HTTPS. Passwords are hashed with scrypt. OAuth credentials and MFA secrets stored in the database are encrypted with the application key. New object uploads request server-side encryption from the storage provider.
Service providers
- DigitalOcean: application infrastructure and object storage.
- OpenAI API: processes user-submitted content for analysis when this AI configuration is used; data sharing for training is disabled.
- Polar: international card checkout and Merchant of Record for applicable transactions.
- SePay: reconciliation of Vietnamese bank-transfer notifications.
Review data-processing details.
Operations and incidents
Health and readiness are monitored regularly; public incidents are recorded on the Status page. NexaFile uses logging, rate limiting, audit records and incident-handling procedures. No system can promise absolute security.
Availability and SLA
NexaFile does not publish a general uptime SLA or service-credit commitment for every plan. Infrastructure-provider SLAs are not NexaFile SLAs. If an enterprise order form includes a separate SLA, only that signed SLA applies.
Public control scope
| Area | Published control | Claim boundary |
|---|---|---|
| Identity & access | MFA · Passkeys · RBAC · audit records | Does not imply third-party certification. |
| Data | HTTPS · encrypted application secrets · workspace isolation | Specific location and retention depend on configuration, providers and contract. |
| Operations | health/readiness monitoring · rate limiting · incident records | Observed measurements are not a contractual SLA. |
Subprocessors and data flow
The list above names currently published providers and their primary purposes. Actual data scope depends on the features a customer uses; not every document is sent to every provider.
NexaFile does not claim SOC 2, ISO 27001 or similar certification unless a current independent report or certificate is available.
Governance, evidence and updates
- Public statements describe controls in operation and must not be elevated into an unsigned certification, SLA or warranty.
- Material changes to providers, OAuth scope, retention or data handling must be reflected in the Trust Center or the applicable legal notice.
- Business customers may request a DPA, security questionnaire or available control evidence; disclosure remains subject to confidentiality and the applicable agreement.
Shared-responsibility model
NexaFile protects the platform and controls it operates. Customers remain responsible for user lifecycle, workspace permissions, endpoint and cloud-account security, lawful data selection, review of AI output and revoking access when no longer needed.
Report a security concern
Send a description, timestamp, affected URL and reproduction steps; do not email passwords, API keys or sensitive documents. [email protected]