Skip to main content
Security & Compliance

Your clients' data.
Protected by design.

NexaSocial is built on enterprise security standards. Every access, every token, every piece of content will be encrypted, audited, and controlled.

What’s protecting your data today

NexaSocial is pre-launch. This site collects only a waitlist email and, for purchases, a display name and billing details — protected today by AES-256-GCM field encryption on stored emails, TLS with HSTS enforced, Cloudflare Turnstile bot protection on every form, and Razorpay’s tokenized checkout (card data never touches our servers).

Everything below — role-based access control, multi-factor authentication, SSO, session management, and the rest — describes the security architecture of the full NexaSocial platform you get early access to. It reflects the real, already-built architecture of that product, not this marketing site; it activates as each part of the platform launches.

Certifications

Built for compliance. Designed to certify.

GDPR

Built to align with EU General Data Protection Regulation requirements. Data Processing Agreement available on request.

CCPA

Built to align with California Consumer Privacy Act requirements. Data deletion requests acknowledged within 3 business days, completed within 30 days.

DPDP Act 2023

Built to align with India's Digital Personal Data Protection Act requirements. Right to erasure implemented.

EU AI Act — Art. 50In progress

In progress: this site has no AI-content-generation feature yet, so labeling/provenance requirements don’t currently apply — tracked ahead of the full product launching that capability.

PCI DSS SAQ-AIn progress

Payments are processed by PCI DSS Level 1 certified providers (Razorpay and Stripe) — card data is tokenized at the gateway and never stored on NexaSocial servers. NexaSocial’s own PCI SAQ-A self-assessment worksheet is in progress and has not yet been completed.

AES-256 Encryption

All data encrypted at rest using AES-256-GCM. TLS 1.3 minimum enforced for all data in transit.

Platform Data Security

Encryption at every layer.

Encryption at rest
AES-256-GCM for all stored data
Encryption in transit
TLS 1.3 minimum
Password hashing
bcrypt, cost factor 12
API tokens
JWT — access: 15 min, refresh: 7 days
Social media tokens
AES-256 encrypted in database
PII fields
Field-level encryption for emails, phone numbers

Platform Access Control

Granular control. Zero trust by default.

Role-Based Access Control

  • 4 global roles: SUPER_ADMIN, ADMIN, USER, VIEWER
  • 4 team roles: OWNER, ADMIN, MEMBER, GUEST
  • Fine-grained permission system per resource

Multi-Factor Authentication

  • TOTP — authenticator apps (Google, Authy)
  • SMS via Twilio (optional)
  • Passkeys — WebAuthn / FIDO2

Single Sign-On

  • SAML 2.0 for Enterprise tier
  • Works with Okta, Azure AD, Google Workspace
  • JIT user provisioning supported

Session Management

  • Device tracking on all active sessions
  • Instant session revocation from dashboard
  • Automatic inactivity timeout

Data Handling

Your data. Your rights.

Data residency

Hosted on enterprise cloud infrastructure. Region selection available on Enterprise tier.

Retention policy

User content retained for 30 days after account deletion, then permanently purged.

Social media tokens

OAuth tokens revoked immediately when a platform is disconnected. No lingering credentials.

Right to erasure

Implemented per GDPR Article 17. We acknowledge requests within 3 business days and complete erasure within 30 days.

Data portability

Full export of your account data available directly from the dashboard at any time.

Responsible disclosure.

Found a vulnerability? We take security research seriously. Report it to us and we'll respond within 24 hours. Good-faith researchers are never subject to legal action.

[email protected]

Need compliance documentation?

Security questionnaires, DPAs, and sub-processor lists are available upon request for Enterprise customers.

Ready to automate your social media?

Reserve your spot free — get early access before the public.