Back to Home

Security

Security is built into NexusHR through layered controls, monitoring, and operational safeguards.

Last updated: April 17, 2026

1. Security Program

NexusHR uses a defense-in-depth approach across application, infrastructure, and operations. Access to production systems is restricted and reviewed, and sensitive changes are logged for auditability.

2. Data Protection Controls

  • encryption in transit using HTTPS/TLS
  • role-based authorization for admin, manager, and employee functions
  • password hashing and secure authentication workflows
  • rate limiting and lockout controls for sensitive endpoints
  • audit and observability logging for critical events

3. Monitoring, Backups, and Resilience

We monitor service health and security events, maintain incident diagnostics, and operate backup and recovery processes to improve continuity and recovery readiness.

4. Shared Responsibility

Customers are responsible for user lifecycle management, secure endpoint practices, and enforcing internal policies. NexusHR is responsible for platform-level safeguards and operational security controls.

5. Security Incident Response

We maintain incident response procedures for detection, containment, remediation, and post-incident review. Where required, affected parties are notified according to contractual and legal obligations.

6. Responsible Disclosure

If you identify a potential vulnerability, please report it to security@nexushr.internal with reproduction details. Please avoid public disclosure until remediation is complete.