Security & Trust

Built for enterprise
trust and security.

NexuSphere is committed to protecting the security of our customers’ data. This page summarizes the key practices and controls we maintain. For more detail, see our Data Processing Addendum and Privacy Policy, or contact us at security@nexusphere.ai.

Human-approved AI

AI recommends — humans approve. NexuSphere AI never takes autonomous action on your data without a person in the loop.

Your data stays yours

Customer data is never used to train shared or third-party AI models.

Encrypted everywhere

Hosted on Google Cloud Platform with TLS 1.2+ in transit and AES-256 at rest.

Access control

Role-based access control with mandatory multi-factor authentication for all accounts.

Infrastructure & Hosting

Our Services are hosted on Google Cloud Platform (GCP) in the United States. GCP maintains its own physical security and environmental controls and holds industry-recognized certifications, including SOC 2 and ISO 27001, for its data centers.

Encryption

Data is encrypted in transit using TLS 1.2 or higher and at rest using Google Cloud Platform’s default AES-256 encryption. Encryption keys are managed through Google Cloud Key Management Service (Google Cloud KMS).

Access Controls

Access to production systems is restricted to authorized personnel on a least-privilege basis and is reviewed periodically. Multi-factor authentication (MFA) is required for all accounts with access to production systems. NexuSphere plans to implement Single Sign-On (SSO) as the organization grows.

AI & Data Handling

NexuSphere does not use Customer Data to train, fine-tune, or evaluate any AI model. AI-generated outputs within the Services are recommendations only and require human review before any action is taken based on them. Full terms are set out in our AI Policy.

Vendor & Sub-processor Management

We carefully evaluate the third-party service providers we rely on to deliver the Services. Our current sub-processors are listed in our Sub-processor List.

Incident Response

We maintain a process to detect, investigate, and respond to security incidents, and we notify affected customers in accordance with our contractual and legal obligations.

Compliance & Certifications

NexuSphere is committed to pursuing SOC 2 Type II certification as the company scales. While certification has not yet been completed, our security program is designed around industry best practices and is documented through our Information Security Policy, Data Processing Addendum, and Security Controls. Security documentation and audit information can be made available to enterprise customers upon request where appropriate.

Responsible Disclosure

If you believe you have discovered a security vulnerability in our Services, please contact us at security@nexusphere.ai. We will investigate reports promptly and appreciate the opportunity to address issues before public disclosure.

Questions about our security practices can be directed to security@nexusphere.ai.

Get Started

Have a security question before you sign up?

We're happy to walk through our architecture and controls directly.

Book a demoStart free pilot

No credit card · 30-day pilot · Direct founder access