How we protect your account
This page describes what is actually in place today. We'll update it as things change, and we won't claim certifications we don't hold.
Accounts and sign-in
- Passwords are hashed with PBKDF2-SHA-256 using a per-password salt and a server-side secret pepper; we never store or log them.
- Two-step verification with authenticator apps (with replay protection), single-use recovery codes and passkeys.
- Sign-in attempts are rate limited per account and per network, with temporary automatic blocks for abusive traffic.
- You can see and end your active sessions and devices at any time; changing your password signs out every other session.
Data
- All traffic uses HTTPS with HSTS. Data is stored on Cloudflare's infrastructure, which encrypts it at rest.
- Session tokens, API keys and one-time links are stored only as keyed hashes. Authenticator secrets are encrypted with AES-256-GCM.
- Every request that reads or changes your data is authorised on the server against your organization, role and product.
- Health and care data is kept separate from other products.
Operations
- Administrator access requires two-step verification, short sessions and re-confirmation for dangerous actions.
- Administrative and security-relevant actions are recorded in an append-only, hash-chained audit log.
- Logs are structured and automatically scrubbed of passwords, tokens and keys.
What we don't claim
NXT CLOUD is not currently certified to SOC 2, ISO 27001 or PCI DSS, and our products are not HIPAA-covered services. Card payments are handled by our payment processor; we never see or store card numbers.
Reporting a vulnerability
If you believe you've found a security problem, please report it privately through our support form (choose “Report a security vulnerability”). Please give us reasonable time to fix it before disclosure, only test against accounts you own, and don't access other people's data or disrupt the service. We won't pursue legal action against good-faith research that follows these rules. See also security.txt.