NXT

Security

Security at NXT

We handle sensitive data during every engagement. That requires our own security posture to be rigorous, transparent, and continuously improving.

How We Handle Your Data

During an assessment, we handle sensitive information about your systems and your business. We treat that data as yours. Assessment findings and documentation are delivered to you directly and are not shared with anyone outside your organization. Working data generated during an engagement is encrypted at rest and deleted after delivery unless a retention period is agreed upon in writing.

Infrastructure

Our internal infrastructure is hosted in the European Union (Germany). All inter-service communication is encrypted with TLS 1.3, and internal systems are authenticated via short-lived, scoped tokens. We maintain strict access controls so that client engagement data is accessible only to the team members working on that engagement.

Compliance

NXT aligns its internal controls with the AICPA Trust Services Criteria and maintains formal policies for access control, incident response, change management, and vendor risk. As our compliance posture matures, we will publish relevant attestation reports for enterprise customers under NDA.

Responsible Disclosure

If you believe you have discovered a security vulnerability in any NXT system, we encourage responsible disclosure. Please contact us at security@nxt-ai.net with a clear description of the issue. We ask that you allow reasonable time for remediation before any public disclosure. We do not pursue legal action against researchers who act in good faith.

For security inquiries, contact security@nxt-ai.net