1. Our approach
Security is a first-class concern in everything Nexsys Tech Limited designs and operates. This policy summarises the technical and organisational measures we apply.
2. Encryption
- All websites we operate are served over HTTPS with modern TLS.
- Sensitive data is encrypted in transit and, where supported by our platforms, at rest.
- Credentials, API keys and secrets are stored using secure secret management, never in plain text.
3. Hosting and infrastructure
- We recommend and use reputable providers with strong physical and network security controls.
- Environments are separated between development, staging and production.
- Least-privilege access is applied to production systems.
4. Authentication and passwords
- Multi-factor authentication is enforced on all critical accounts where the service supports it.
- Passwords are unique, high-entropy and rotated where compromise is suspected.
- Client credentials shared with us are handled through secure channels and deleted after use where appropriate.
5. Backups
- Where hosting arrangements permit, regular automated backups are configured.
- Backups are stored securely and tested periodically.
6. Firewalls, monitoring and logging
- Web application firewalls and rate limiting are used where appropriate.
- Server and application logs are collected and monitored for suspicious activity.
- Alerts are configured for anomalous access and error patterns.
7. Patching and updates
- Operating systems, frameworks and dependencies are kept up to date under our maintenance plans.
- Critical security updates are applied on a priority basis.
8. Secure development
- Code is reviewed with security in mind, following OWASP guidance.
- Input is validated and output escaped to guard against injection and cross-site scripting.
- Dependencies are monitored for known vulnerabilities.
9. Responsible disclosure
If you believe you have discovered a security vulnerability in this website or any Nexsys Tech-operated system, please report it responsibly:
- Email nexsys.te@gmail.com with details of the issue and steps to reproduce.
- Give us a reasonable opportunity to investigate and fix the issue before public disclosure.
- Do not access, modify or delete data beyond what is necessary to demonstrate the issue.
- Do not perform denial-of-service tests or attacks that impact availability.
We appreciate responsible security research and will acknowledge legitimate reports promptly.
10. Incident response
In the event of a personal data breach, we will investigate, contain and remediate as quickly as possible, notify affected clients where required, and report to the ICO within 72 hours where the breach meets the statutory threshold.
11. Contact
Security contact: nexsys.te@gmail.com.
