NEXAFILE · TRUST CENTER

Trust Center

A public overview of NexaFile security, access, providers and availability. This page is not a contractual SLA.

Access controls

Encryption and data transfer

Production browser connections use HTTPS. Passwords are hashed with scrypt. OAuth credentials and MFA secrets stored in the database are encrypted with the application key. New object uploads request server-side encryption from the storage provider.

Service providers

Review data-processing details.

Operations and incidents

Health and readiness are monitored regularly; public incidents are recorded on the Status page. NexaFile uses logging, rate limiting, audit records and incident-handling procedures. No system can promise absolute security.

View service status

Availability and SLA

NexaFile does not publish a general uptime SLA or service-credit commitment for every plan. Infrastructure-provider SLAs are not NexaFile SLAs. If an enterprise order form includes a separate SLA, only that signed SLA applies.

SLA Droplet · SLA Spaces

Public control scope

AreaPublished controlClaim boundary
Identity & accessMFA · Passkeys · RBAC · audit recordsDoes not imply third-party certification.
DataHTTPS · encrypted application secrets · workspace isolationSpecific location and retention depend on configuration, providers and contract.
Operationshealth/readiness monitoring · rate limiting · incident recordsObserved measurements are not a contractual SLA.

Subprocessors and data flow

The list above names currently published providers and their primary purposes. Actual data scope depends on the features a customer uses; not every document is sent to every provider.

NexaFile does not claim SOC 2, ISO 27001 or similar certification unless a current independent report or certificate is available.

Governance, evidence and updates

Shared-responsibility model

NexaFile protects the platform and controls it operates. Customers remain responsible for user lifecycle, workspace permissions, endpoint and cloud-account security, lawful data selection, review of AI output and revoking access when no longer needed.

Report a security concern

Send a description, timestamp, affected URL and reproduction steps; do not email passwords, API keys or sensitive documents. [email protected]

NexaFile AI assistant AI