What’s protecting your data today
NexaSocial is pre-launch. This site collects only a waitlist email and, for purchases, a display name and billing details — protected today by AES-256-GCM field encryption on stored emails, TLS with HSTS enforced, Cloudflare Turnstile bot protection on every form, and Razorpay’s tokenized checkout (card data never touches our servers).
Everything below — role-based access control, multi-factor authentication, SSO, session management, and the rest — describes the security architecture of the full NexaSocial platform you get early access to. It reflects the real, already-built architecture of that product, not this marketing site; it activates as each part of the platform launches.
Certifications
Built for compliance. Designed to certify.
GDPR
Built to align with EU General Data Protection Regulation requirements. Data Processing Agreement available on request.
CCPA
Built to align with California Consumer Privacy Act requirements. Data deletion requests acknowledged within 3 business days, completed within 30 days.
DPDP Act 2023
Built to align with India's Digital Personal Data Protection Act requirements. Right to erasure implemented.
EU AI Act — Art. 50In progress
In progress: this site has no AI-content-generation feature yet, so labeling/provenance requirements don’t currently apply — tracked ahead of the full product launching that capability.
PCI DSS SAQ-AIn progress
Payments are processed by PCI DSS Level 1 certified providers (Razorpay and Stripe) — card data is tokenized at the gateway and never stored on NexaSocial servers. NexaSocial’s own PCI SAQ-A self-assessment worksheet is in progress and has not yet been completed.
AES-256 Encryption
All data encrypted at rest using AES-256-GCM. TLS 1.3 minimum enforced for all data in transit.
Platform Data Security
Encryption at every layer.
Platform Access Control
Granular control. Zero trust by default.
Role-Based Access Control
- 4 global roles: SUPER_ADMIN, ADMIN, USER, VIEWER
- 4 team roles: OWNER, ADMIN, MEMBER, GUEST
- Fine-grained permission system per resource
Multi-Factor Authentication
- TOTP — authenticator apps (Google, Authy)
- SMS via Twilio (optional)
- Passkeys — WebAuthn / FIDO2
Single Sign-On
- SAML 2.0 for Enterprise tier
- Works with Okta, Azure AD, Google Workspace
- JIT user provisioning supported
Session Management
- Device tracking on all active sessions
- Instant session revocation from dashboard
- Automatic inactivity timeout
Data Handling
Your data. Your rights.
Data residency
Hosted on enterprise cloud infrastructure. Region selection available on Enterprise tier.
Retention policy
User content retained for 30 days after account deletion, then permanently purged.
Social media tokens
OAuth tokens revoked immediately when a platform is disconnected. No lingering credentials.
Right to erasure
Implemented per GDPR Article 17. We acknowledge requests within 3 business days and complete erasure within 30 days.
Data portability
Full export of your account data available directly from the dashboard at any time.
Responsible disclosure.
Found a vulnerability? We take security research seriously. Report it to us and we'll respond within 24 hours. Good-faith researchers are never subject to legal action.
[email protected]