Trust
Security
SOC 2 Type II, ISO 27001 and encryption everywhere by default.
SOC 2 Type II, ISO 27001, 27017 and 27018, encryption everywhere, and a funded bug bounty with public triage times.
- Certifications
- SOC 2 II · ISO 27001/17/18
- Bounty
- Up to $50,000
- Triage
- Median 6 hours
Controls in place
Data protection
- AES-256 at rest, TLS 1.3 in transit
- Customer-managed keys via KMS
- Field-level encryption helpers
- 35–365 day point-in-time recovery
Access
- SSO with SAML and OIDC
- SCIM provisioning and deprovisioning
- Hardware-key enforced admin access
- Just-in-time production access with review
Assurance
- Annual third-party penetration test
- Continuous control monitoring
- Immutable audit log export
- Published sub-processor list
Compliance artefacts
| Artefact | Availability | Refresh |
|---|---|---|
| SOC 2 Type II report | Under NDA | Annual |
| ISO 27001 certificate | Public | Annual |
| Penetration test summary | Under NDA | Annual |
| DPA and sub-processor list | Public | On change |
| BAA (healthcare) | On request | On signature |
| Security questionnaire pack | Public | Quarterly |
Responsible disclosure
01
Report
Email security@nazexa.com with the PGP key published on this page, or submit through the bounty platform.
02
Triage
Median first response of six hours, with a severity assessment and a named engineer within one business day.
03
Reward and disclose
Bounties from $500 to $50,000 paid on fix verification, with coordinated public disclosure after remediation.
Frequently asked
Request the evidence pack
Sales can send the SOC 2 report, penetration test summary and questionnaire answers within one business day.