NazexaNazexa
Trust

Security 

SOC 2 Type II, ISO 27001 and encryption everywhere by default.

SOC 2 Type II, ISO 27001, 27017 and 27018, encryption everywhere, and a funded bug bounty with public triage times.

Certifications
SOC 2 II · ISO 27001/17/18
Bounty
Up to $50,000
Triage
Median 6 hours

Controls in place

Data protection

  • AES-256 at rest, TLS 1.3 in transit
  • Customer-managed keys via KMS
  • Field-level encryption helpers
  • 35–365 day point-in-time recovery

Access

  • SSO with SAML and OIDC
  • SCIM provisioning and deprovisioning
  • Hardware-key enforced admin access
  • Just-in-time production access with review

Assurance

  • Annual third-party penetration test
  • Continuous control monitoring
  • Immutable audit log export
  • Published sub-processor list

Compliance artefacts

ArtefactAvailabilityRefresh
SOC 2 Type II reportUnder NDAAnnual
ISO 27001 certificatePublicAnnual
Penetration test summaryUnder NDAAnnual
DPA and sub-processor listPublicOn change
BAA (healthcare)On requestOn signature
Security questionnaire packPublicQuarterly

Responsible disclosure

01

Report

Email security@nazexa.com with the PGP key published on this page, or submit through the bounty platform.

02

Triage

Median first response of six hours, with a severity assessment and a named engineer within one business day.

03

Reward and disclose

Bounties from $500 to $50,000 paid on fix verification, with coordinated public disclosure after remediation.

Frequently asked

Request the evidence pack

Sales can send the SOC 2 report, penetration test summary and questionnaire answers within one business day.